CVE-2026-5198: Code-Projects Student Membership System

High severity, CVSS 7.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability was determined in code-projects Student Membership System 1.0. The impacted element is an unknown function of the file /admin/index.php of the component Admin Login. This manipulation of the argument username/password causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

Affected products

Published 2026-03-31. Last modified 2026-07-24.