Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Student-Management-System — Vulnerabilities & Security Advisories 28

All 28 CVE vulnerabilities found in Student-Management-System, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with the Student-Management-System product, specifically focusing on software weaknesses and their corresponding vendor advisories. It collects a comprehensive set of security flaws reported for this educational platform, covering the period from its initial release through the most recent updates. Readers can use this resource to track the vendor’s advisory history, understand specific weakness classes affecting student data handling, and review the complete vulnerability timeline for this system. The entries are organized to facilitate analysis of recurring issues, such as authentication bypasses or data exposure risks, without requiring external cross-referencing. By consolidating these records, the page provides a centralized view of the product’s security posture over time. This allows security professionals and administrators to identify patterns in reported defects, assess the frequency of critical patches, and evaluate the long-term stability of the software. The aggregation includes both publicly disclosed issues and those identified through internal audits, ensuring a broad perspective on potential risks. Users can filter entries by severity level or vulnerability type to focus on specific concerns relevant to their operational environment. This structured approach supports informed decision-making regarding patch management and risk mitigation strategies for institutions relying on this student management infrastructure.

Vendor: Cyber-III

CVE ID Title CVSS Severity Published
CVE-2026-97650 ningzichun student-management-system addLog.php echo cross site scripting CWE-79 4.3 Medium 2026-09-25
CVE-2026-97649 ningzichun student-management-system example_lite.sql default credentials CWE-1392 4.7 Medium 2026-09-25
CVE-2026-97648 ningzichun student-management-system cross-site request forgery CWE-352 4.3 Medium 2026-09-25
CVE-2026-97647 ningzichun student-management-system editLog.php authorization CWE-639 5.3 Medium 2026-09-25
CVE-2026-97646 ningzichun student-management-system getStudent.php authorization CWE-639 7.3 High 2026-09-25
CVE-2026-82698 sambitraj Student-Management-System aca.sql default password CWE-1393 5.3 Medium 2026-08-31
CVE-2026-82697 sambitraj Student-Management-System session_start cookie httponly flag CWE-1004 3.7 Low 2026-08-31
CVE-2026-78057 sambitraj Student-Management-System Management Mutation sql injection CWE-89 6.3 Medium 2026-08-23
CVE-2026-78056 sambitraj Student-Management-System Dashboard sql injection CWE-89 6.3 Medium 2026-08-23
CVE-2026-18958 imranrisal-dev Student-Management-System Login loginCheckTest.php sql injection CWE-89 7.3 High 2026-08-05
CVE-2026-18927 imranrisal-dev Student-Management-System Shared Upload Helper student_profile_pic.php storeProfileImage unrestricted upload CWE-434 6.3 Medium 2026-08-05
CVE-2026-11476 Kushan2k student-management-system Profile Update Endpoint AdminController.php edit-admin improper authorization CWE-285 6.3 Medium 2026-06-08
CVE-2026-11475 Kushan2k student-management-system Certificate Verification Endpoint GradeController.php getStatus sql injection CWE-89 6.3 Medium 2026-06-08
CVE-2026-11474 Kushan2k student-management-system Registration Endpoint RegisterService.php unrestricted upload CWE-434 7.3 High 2026-06-08
CVE-2026-10777 ealpha072 Student-Management-System Administrative Backend config.php improper authentication CWE-287 7.3 High 2026-06-03
CVE-2026-10619 sayan365 student-management-system improper authentication CWE-287 7.3 High 2026-06-02
CVE-2026-10272 a4m4 Student-Management-System deleteform.php improper authorization CWE-285 6.5 Medium 2026-06-01
CVE-2026-10271 a4m4 Student-Management-System Admin Endpoint admin redirect CWE-698 6.3 Medium 2026-06-01
CVE-2026-10112 sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard cross site scripting CWE-79 2.4 Low 2026-05-30
CVE-2026-10111 sambitraj STUDENT-MANAGEMENT-SYSTEM Login Page sql injection CWE-89 7.3 High 2026-05-30
CVE-2026-9562 sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard access control CWE-284 7.3 High 2026-05-26
CVE-2026-5671 Cyber-III Student-Management-System Class Schedule Deletion Endpoint delete_batch.php cross site scripting CWE-79 4.3 Medium 2026-04-06
CVE-2026-5670 Cyber-III Student-Management-System upload.php move_uploaded_file unrestricted upload CWE-434 6.3 Medium 2026-04-06
CVE-2026-5669 Cyber-III Student-Management-System Parameter login.php sql injection CWE-89 7.3 High 2026-04-06
CVE-2026-5668 Cyber-III Student-Management-System add%20notice.php cross site scripting CWE-79 2.4 Low 2026-04-06
CVE-2026-5644 Cyber-III Student-Management-System batch-notice.php cross site scripting CWE-79 2.4 Low 2026-04-06
CVE-2026-5643 Cyber-III Student-Management-System Admin Add Endpoint notice.php cross site scripting CWE-79 2.4 Low 2026-04-06
CVE-2026-5642 Cyber-III Student-Management-System HTTP POST Request update.php improper authorization CWE-285 7.3 High 2026-04-06

All 28 known CVE vulnerabilities affecting Student-Management-System with full Chinese analysis, references, and POCs where available.