Itsourcecode develops a focused portfolio of web-based educational management and laboratory systems, including student enrollment, school administration, and information management platforms that serve institutional deployments. Vulnerabilities affecting this vendor skew strongly toward critical severity and concentrate heavily in injection-class weaknesses—SQL injection, code injection, and cross-site scripting—alongside file-upload validation issues, reflecting the vendor's reliance on web-application frameworks handling untrusted user input from students, staff, and administrators. These weakness classes recur across the vendor's product line and are characteristic of educational software that must process and display diverse data from a wide user base without adequate input sanitization. Defenders should prioritize inventory and isolation of these systems from untrusted networks and apply patches immediately upon availability. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Itsourcecode over time
Signals from CVEs in this vendor scope (69 CVEs).
69 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-1176CRITICAL A security flaw has been discovered in itsourcecode School Management System 1.0. Affected is an unknown function of the file /subject/index.php. Performing a manipulation of the a | Jan 19, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-9838CRITICAL A vulnerability was identified in itsourcecode Student Information Management System 1.0. Impacted is an unknown function of the file /admin/modules/subject/index.php. Such manipul | Sep 2, 2025 | 9.8 | 34 | NO | NO |
CVE-2026-2018CRITICAL A flaw has been found in itsourcecode School Management System 1.0. This affects an unknown part of the file /ramonsys/settings/controller.php. This manipulation of the argument ID | Feb 6, 2026 | 9.8 | 33 | NO | NO |
CVE-2025-13299CRITICAL A flaw has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. This impacts an unknown function of the file /user/controller.php. Executing a manipulati | Nov 17, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-9837CRITICAL A vulnerability was determined in itsourcecode Student Information Management System 1.0. This issue affects some unknown processing of the file /admin/modules/student/index.php. T | Sep 2, 2025 | 9.8 | 33 | NO | NO |
CVE-2026-3730CRITICAL A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1.0. The affected element is an unknown function of the file /hotel/admin/mod_amenities/index.php? | Mar 8, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-3261CRITICAL A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settings/index.php of the component Setting Handler. This manipula | Feb 26, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-2014CRITICAL A security flaw has been discovered in itsourcecode Student Management System 1.0. This impacts an unknown function of the file /ramonsys/billing/index.php. Performing a manipulati | Feb 6, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-2013CRITICAL A vulnerability was identified in itsourcecode Student Management System 1.0. This affects an unknown function of the file /ramonsys/soa/index.php. Such manipulation of the argumen | Feb 6, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-2012CRITICAL A vulnerability was determined in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /ramonsys/facultyloading/index.php. This manip | Feb 6, 2026 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (69 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Itsourcecode.
Media articles that mention a CVE ID that affects a product developed by Itsourcecode — matched by CVE ID, not by vendor name.