Mathurvishal CloudClassroom-PHP-Project: 18 SQLi, XSS, and Auth Bypass Flaws Disclosed Together
Mathurvishal CloudClassroom-PHP-Project: 18 vulnerabilities, including SQLi and XSS, disclosed with some having public exploits.

Key findings
- 18 vulnerabilities disclosed for Mathurvishal CloudClassroom-PHP-Project between Sep 25-28, 2026.
- Batch includes high-severity SQL injection and medium-severity XSS flaws.
- Multiple CVEs have publicly available exploits, posing an immediate risk.
- Affected versions are up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be.
- Users should update to the latest patched version to mitigate risks.
On September 25-28, 2026, a batch of 18 vulnerabilities was disclosed for the Mathurvishal CloudClassroom-PHP-Project. The vulnerabilities, ranging in severity from Low to High, were all found in versions up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Many of these flaws allow for remote exploitation, with several having publicly available exploits.
The disclosed vulnerabilities primarily fall into two categories: SQL injection and Cross-Site Scripting (XSS).
SQL Injection Vulnerabilities: A significant number of the disclosed CVEs are SQL injection flaws, affecting various files within the project. These include:
updateresultdetails.php(CVE-2026-101013)makeresult.php(CVE-2026-101012)updatedetailsfromfaculty.php(CVE-2026-100875)addnewstudent.php(CVE-2026-100874)viewresult.php(CVE-2026-100739)mydetailsfaculty.php(CVE-2026-100315)updatedetailsfromstudent.php(CVE-2026-100314)updateguest.php(CVE-2026-100312)managevideos2.php(CVE-2026-97886)updatefaculty.php(CVE-2026-97885)updatestudent.php(CVE-2026-97884)updatequery.php(CVE-2026-97883)loginlinkfaculty.php(CVE-2026-97882)
These SQL injection vulnerabilities are typically triggered by manipulating specific arguments within these files, allowing attackers to inject malicious SQL code and potentially access or modify sensitive data.
Cross-Site Scripting (XSS) Vulnerabilities: Several XSS vulnerabilities were also part of this disclosure:
registrationform.php(CVE-2026-100877)updatequery.php(CVE-2026-100313)managevideos2.php(CVE-2026-100311)
These flaws arise from improper sanitization of user inputs, allowing attackers to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking or other malicious actions.
Authentication Bypass and CSRF: Additionally, the batch includes an authentication bypass vulnerability in loginlinkstudent.php (CVE-2026-100876) and a Cross-Site Request Forgery (CSRF) vulnerability in an unspecified function (CVE-2026-100873).
Exploitation and Response: Multiple CVEs in this batch have publicly available exploits, increasing the risk for unpatched systems. The vulnerabilities affect versions up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Users are strongly advised to update their CloudClassroom-PHP-Project installations to a patched version as soon as possible to mitigate these risks. Specific patch versions were not detailed in the disclosures, but updating to the latest available commit is recommended.
This large disclosure of 18 vulnerabilities, many with known exploits, highlights a critical need for users of the Mathurvishal CloudClassroom-PHP-Project to prioritize security updates. The prevalence of SQL injection and XSS flaws indicates potential weaknesses in input validation and data handling within the application.
The batch of vulnerabilities was disclosed between September 25 and September 28, 2026. The affected commit hash is 5dadec098bfbbf3300d60c3494db3fb95b66e7be.
Key vulnerabilities include:
- Multiple high-severity SQL injection flaws across various files.
- Medium-severity Cross-Site Scripting (XSS) vulnerabilities.
- An authentication bypass vulnerability in student login.
- A Cross-Site Request Forgery (CSRF) vulnerability.
- Several CVEs have publicly available exploits, increasing immediate risk.
All users of the Mathurvishal CloudClassroom-PHP-Project should update to a version beyond commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be to address these security issues.
CVE-2026-101013, CVE-2026-101012, CVE-2026-100877, CVE-2026-100876, CVE-2026-100875, CVE-2026-100874, CVE-2026-100873, CVE-2026-100739, CVE-2026-100315, CVE-2026-100314, CVE-2026-100313, CVE-2026-100312, CVE-2026-100311, CVE-2026-97886, CVE-2026-97885, CVE-2026-97884, CVE-2026-97883, CVE-2026-97882