VYPR
advisoryPublished Sep 8, 2026· 1 source

Code Projects: 19 Vulnerabilities Including SQLi and Info Disclosure Disclosed Together

Key findings • 19 vulnerabilities disclosed in Code Projects applications between September 3-8, 2026. • Batch includes SQL injection, information disclosure, and XSS flaws across multiple pr…

Key findings

  • 19 vulnerabilities disclosed in Code Projects applications between September 3-8, 2026.
  • Batch includes SQL injection, information disclosure, and XSS flaws across multiple products.
  • High-severity SQL injection flaws (CVSSv3 7.3) affect Doctor Appointment and Hospital Information Systems.
  • Exploits for many of these vulnerabilities are publicly available, increasing immediate risk.
  • Affected applications are primarily version 1.0; patches are reportedly available for some systems.

On September 8, 2026, a batch of 19 vulnerabilities was disclosed across multiple Code Projects applications, spanning a disclosure window from September 3rd to September 8th, 2026. The vulnerabilities, primarily SQL injection and information disclosure flaws, affect various versions of the company's software, with many exploits publicly available and potentially in use.

The disclosed vulnerabilities can be broadly categorized by their impact and affected components. A significant cluster of SQL injection flaws, many rated as High severity (CVSSv3 7.3), were found in several applications:

Several instances of information disclosure vulnerabilities were also identified, mostly related to backup file handlers:

Additionally, cross-site scripting (XSS) vulnerabilities were found in:

According to related reporting from Vypr Intelligence, six high-severity SQL injection vulnerabilities affecting the Doctor Appointment System and Hospital Information System (CVE-2026-85225, CVE-2026-85397, CVE-2026-85398, CVE-2026-85399, CVE-2026-85402, CVE-2026-85403) were disclosed on September 4, 2026. Exploits for these specific flaws are publicly available, increasing the immediate risk to users of these systems.

The majority of these vulnerabilities, particularly the SQL injection flaws, are remotely exploitable and have publicly available exploits, indicating a significant risk to users who have not yet updated their systems. The affected applications are typically version 1.0. While specific patch details for each CVE are not provided in the batch, the reporting suggests that patches are available for the Doctor Appointment System and Hospital Information System. Users are strongly advised to consult vendor advisories for specific version information and apply updates promptly.

This large batch of vulnerabilities underscores the importance of regular security audits and timely patching for Code Projects applications. The widespread nature of these flaws, affecting multiple products and including critical vulnerabilities with public exploits, necessitates immediate attention from system administrators and users to mitigate potential security risks.

CVE-2026-86519, CVE-2026-86518, CVE-2026-86302, CVE-2026-86301, CVE-2026-86217, CVE-2026-86216, CVE-2026-86180, CVE-2026-86179, CVE-2026-86181, CVE-2026-86168, CVE-2026-85643, CVE-2026-85517, CVE-2026-85516, CVE-2026-85403, CVE-2026-85402, CVE-2026-85399, CVE-2026-85398, CVE-2026-85397, CVE-2026-85225

Synthesized by Vypr AI