VYPR
Vypr IntelligenceAI-generatedAug 25, 2026· 5 CVEs

Code Projects: Five SQLi, XSS, and Auth Bypass Flaws Disclosed Together

Code Projects systems affected by a batch of five vulnerabilities including SQLi, XSS, and auth bypass flaws, with public exploits available for some.

Key findings

  • Five vulnerabilities disclosed in Code Projects systems between August 23-25, 2026.
  • Includes two High-severity SQL injection flaws in Simple Inventory System and Barangay Resident Profiling Management System.
  • Also features two Medium-severity authorization bypass flaws in Barangay Resident Profiling Management System.
  • One Medium-severity XSS vulnerability found in Online Shopping System.
  • Publicly available exploits noted for some of the disclosed vulnerabilities.

On August 23-25, 2026, a batch of five vulnerabilities was disclosed across three distinct products from Code Projects, a vendor known for its open-source management systems. The vulnerabilities, spanning SQL injection, cross-site scripting (XSS), and authorization bypass flaws, were published over a two-day period, highlighting potential security weaknesses in systems such as the Simple Inventory System, Online Shopping System, and Barangay Resident Profiling Management System.

Two of the disclosed vulnerabilities, CVE-2026-79845 and CVE-2026-78143, are rated as High severity with a CVSSv3 score of 7.3. CVE-2026-79845, found in the Simple Inventory System 1.0, is an SQL injection vulnerability in the /InventoryManagement/edit.php file, exploitable remotely due to manipulation of the 'ID' argument. Similarly, CVE-2026-78143, affecting the Barangay Resident Profiling Management System 1.0, is an SQL injection flaw within the Resident Search Functionality (/residents.php), triggered by manipulating the 'Search' argument. The public availability of exploits for these high-severity issues warrants immediate attention from users.

The remaining three vulnerabilities, all rated Medium severity, include two authorization bypass flaws and one XSS vulnerability. CVE-2026-78144 and CVE-2026-78142, both impacting the Barangay Resident Profiling Management System 1.0, are authorization bypass vulnerabilities. The former resides in the Boarder Management Module (/boarders.php) via the 'ID' argument, while the latter is located in the Restore/Delete component (/archived_records.php) through manipulation of the 'resident_id' argument. The third medium-severity vulnerability, CVE-2026-79793, found in the Online Shopping System 1.0, is a cross-site scripting (XSS) flaw within the /admin/sumit_form.php file, stemming from the manipulation of the 'Success' argument. Public disclosure of exploits for some of these issues has been noted.

The affected products and their specific versions are:

Details regarding patches or specific version updates were not provided in the disclosure information. However, the nature of these vulnerabilities, particularly the SQL injection and authorization bypass flaws, suggests that users should prioritize updating their systems to the latest available versions once patches are released by Code Projects. The remote exploitability of several of these flaws, coupled with the public availability of exploits for some, increases the risk for unpatched systems.

This batch of disclosures underscores the importance of regular security audits and prompt patching for users of Code Projects' management systems. The variety of vulnerabilities across different products indicates a need for a comprehensive security review by the vendor and diligent attention to updates by the user base.

CVE-2026-79845 CVE-2026-79793 CVE-2026-78144 CVE-2026-78143 CVE-2026-78142

AI-written article. Grounded in 5 CVE records listed below.