CVE-2026-86278: Sourcecodester Syllabus-Aligned Learning Management & Examination System

Medium severity, CVSS 4.3. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected element is an unknown function of the file manage_subjects.php. The manipulation of the argument msg/title/content results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used.

Affected products

  • Sourcecodester Syllabus-Aligned Learning Management & Examination System: version 1.0 only

Published 2026-09-07. Last modified 2026-09-08.