Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Student-Management-System — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in Student-Management-System, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities for the Student-Management-System product, focusing on common weakness types and associated security tags. It compiles data on security flaws ranging from SQL injection and cross-site scripting to authentication bypasses and insecure direct object references, covering incidents reported from early 2020 through the present date. Here, you can track the vendor's historical advisories to monitor response times and patch availability, gain a deeper understanding of specific weakness classes by analyzing recurring patterns, and look up the product's comprehensive vulnerability history to assess long-term security posture and risk exposure. This resource is designed for security analysts, system administrators, and IT managers who need to evaluate the integrity and resilience of student management infrastructures against evolving threat landscapes. By centralizing this information, the page facilitates informed decision-making regarding system updates, mitigation strategies, and compliance audits. Users are encouraged to cross-reference the listed weaknesses with official vendor statements and third-party security databases to ensure the accuracy and completeness of the findings. The goal is to provide a clear, factual overview that supports proactive security management without introducing speculative commentary or biased evaluations. All entries are derived from verified reports and public disclosures to maintain high standards of reliability and trustworthiness for professional use.

Vendor: Cyber-III

CVE IDTitleCVSSSeverityPublished
CVE-2026-11476 Kushan2k student-management-system Profile Update Endpoint AdminController.php edit-admin improper authorization CWE-285 6.3 Medium2026-06-08
CVE-2026-11475 Kushan2k student-management-system Certificate Verification Endpoint GradeController.php getStatus sql injection CWE-89 6.3 Medium2026-06-08
CVE-2026-11474 Kushan2k student-management-system Registration Endpoint RegisterService.php unrestricted upload CWE-434 7.3 High2026-06-08
CVE-2026-10777 ealpha072 Student-Management-System Administrative Backend config.php improper authentication CWE-287 7.3 High2026-06-03
CVE-2026-10619 sayan365 student-management-system improper authentication CWE-287 7.3 High2026-06-02
CVE-2026-10272 a4m4 Student-Management-System deleteform.php improper authorization CWE-285 6.5 Medium2026-06-01
CVE-2026-10271 a4m4 Student-Management-System Admin Endpoint admin redirect CWE-698 6.3 Medium2026-06-01
CVE-2026-10112 sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard cross site scripting CWE-79 2.4 Low2026-05-30
CVE-2026-10111 sambitraj STUDENT-MANAGEMENT-SYSTEM Login Page sql injection CWE-89 7.3 High2026-05-30
CVE-2026-9562 sambitraj STUDENT-MANAGEMENT-SYSTEM Dashboard access control CWE-284 7.3 High2026-05-26
CVE-2026-5671 Cyber-III Student-Management-System Class Schedule Deletion Endpoint delete_batch.php cross site scripting CWE-79 4.3 Medium2026-04-06
CVE-2026-5670 Cyber-III Student-Management-System upload.php move_uploaded_file unrestricted upload CWE-434 6.3 Medium2026-04-06
CVE-2026-5669 Cyber-III Student-Management-System Parameter login.php sql injection CWE-89 7.3 High2026-04-06
CVE-2026-5668 Cyber-III Student-Management-System add%20notice.php cross site scripting CWE-79 2.4 Low2026-04-06
CVE-2026-5644 Cyber-III Student-Management-System batch-notice.php cross site scripting CWE-79 2.4 Low2026-04-06
CVE-2026-5643 Cyber-III Student-Management-System Admin Add Endpoint notice.php cross site scripting CWE-79 2.4 Low2026-04-06
CVE-2026-5642 Cyber-III Student-Management-System HTTP POST Request update.php improper authorization CWE-285 7.3 High2026-04-06

All 17 known CVE vulnerabilities affecting Student-Management-System with full Chinese analysis, references, and POCs where available.