Itsourcecode: 17 SQLi Flaws with Public Exploits Disclosed Together
A batch of 17 SQL injection vulnerabilities, all with public exploits, was disclosed for Itsourcecode's Sales and Inventory System and other products between September 6-8, 2026.

Key findings
- 17 SQL injection vulnerabilities disclosed for Itsourcecode products between September 6-8, 2026.
- All vulnerabilities have publicly available exploits, increasing immediate risk.
- The majority of flaws affect Itsourcecode Sales and Inventory System 1.0.
- One high-severity SQL injection affects Itsourcecode School Management System 1.0.
- No vendor advisories or patches were immediately available at the time of disclosure.
On September 7, 2026, a batch of 17 SQL injection vulnerabilities was disclosed for Itsourcecode's Sales and Inventory System 1.0 and other products. The vulnerabilities, spanning from September 6 to September 8, 2026, were all publicly disclosed with exploits available, posing a significant risk to users. The majority of these flaws affect the Sales and Inventory System 1.0, with a few impacting other Itsourcecode products like the School Management System 1.0 and Information System Society Membership System 1.0.
The vulnerabilities primarily stem from improper handling of user-supplied input in various PHP files, allowing remote attackers to inject malicious SQL queries. This class of vulnerability, SQL injection, can lead to unauthorized data access, modification, or deletion.
Specifically, the Sales and Inventory System 1.0 is affected by numerous SQL injection flaws across multiple files including /pages/us_searchfrm.php, /pages/cust_edit1.php, /pages/pro_searchfrm.php, /pages/us_edit1.php, /pages/settings_edit.php, /pages/emp_edit1.php, /pages/us_transac.php, /pages/sup_transac.php, /pages/pro_transac.php, /pages/pos_transac.php, /pages/cust_transac.php, /pages/us_del.php, /pages/sup_del.php, /pages/trans_view.php, and /pages/pro_del.php. In each case, manipulation of arguments such as ID, Username, companyname, Name, Customer, firstname, and student_id leads to SQL injection.
Beyond the Sales and Inventory System, CVE-2026-86268, a high-severity SQL injection vulnerability, affects Itsourcecode's School Management System 1.0 in the User_Login.php file via manipulation of the email argument. Additionally, CVE-2026-86267 impacts the Information System Society Membership System 1.0 in /society/check_student.php through manipulation of the student_id argument.
All 17 disclosed vulnerabilities share a common characteristic: the availability of public exploits. This significantly increases the risk, as malicious actors can readily leverage these exploits to compromise affected systems. The consistent pattern of SQL injection across various components and products suggests a systemic issue in how Itsourcecode handles user input.
As of the disclosure, no specific vendor advisories or patch information were provided for this batch of vulnerabilities. Users are strongly advised to exercise extreme caution and seek any available updates or security guidance directly from Itsourcecode. The widespread nature of these SQL injection flaws across multiple products underscores the urgent need for patching and security diligence for all Itsourcecode customers.
The disclosure of 17 SQL injection vulnerabilities, all with public exploits, highlights a critical security posture for Itsourcecode products. The consistent pattern of these flaws across different systems and files indicates a potential need for a comprehensive security review by the vendor. Users of Itsourcecode's Sales and Inventory System 1.0, School Management System 1.0, and Information System Society Membership System 1.0 should prioritize investigating and applying any available security updates to mitigate the risk of exploitation.
Key Findings:
- 17 SQL injection vulnerabilities disclosed for Itsourcecode products between September 6-8, 2026.
- All vulnerabilities have publicly available exploits, increasing immediate risk.
- The majority of flaws affect Itsourcecode Sales and Inventory System 1.0.
- One high-severity SQL injection affects Itsourcecode School Management System 1.0.
- No vendor advisories or patches were immediately available at the time of disclosure.
CVE IDs: CVE-2026-86517, CVE-2026-86310, CVE-2026-86309, CVE-2026-86291, CVE-2026-86270, CVE-2026-86269, CVE-2026-86268, CVE-2026-86267, CVE-2026-86265, CVE-2026-86245, CVE-2026-86236, CVE-2026-86235, CVE-2026-86234, CVE-2026-86233, CVE-2026-86232, CVE-2026-86164, CVE-2026-86163