Code Projects: 19 Vulnerabilities Including SQLi and Info Disclosure Disclosed Together
Key findings • 19 vulnerabilities disclosed in Code Projects applications between September 3-8, 2026. • Batch includes SQL injection, information disclosure, and XSS flaws across multiple pr…

Key findings
- 19 vulnerabilities disclosed in Code Projects applications between September 3-8, 2026.
- Batch includes SQL injection, information disclosure, and XSS flaws across multiple products.
- High-severity SQL injection flaws (CVSSv3 7.3) affect Doctor Appointment and Hospital Information Systems.
- Exploits for many of these vulnerabilities are publicly available, increasing immediate risk.
- Affected applications are primarily version 1.0; patches are reportedly available for some systems.
On September 8, 2026, a batch of 19 vulnerabilities was disclosed across multiple Code Projects applications, spanning a disclosure window from September 3rd to September 8th, 2026. The vulnerabilities, primarily SQL injection and information disclosure flaws, affect various versions of the company's software, with many exploits publicly available and potentially in use.
The disclosed vulnerabilities can be broadly categorized by their impact and affected components. A significant cluster of SQL injection flaws, many rated as High severity (CVSSv3 7.3), were found in several applications:
- **Doctor Appointment System 1.0**: CVE-2026-85403 in
/contactus.php, CVE-2026-85402 in/patient/booking.php, and CVE-2026-85225 in/patient_login.php. - **Hospital Information System 1.0**: CVE-2026-85399 in
includes/presp/PrespController.php, CVE-2026-85398 inviewReq.php, and CVE-2026-85397 inaddReq.php. - **Vehicle Management System 1.0**: CVE-2026-85516 in
/busprofile.php. - **Task Management System In PHP 1.0**: CVE-2026-86180 in
/index.php. - **Content Management System 1.0**: CVE-2026-86168 in
/login.php. - **Online Shopping System 1.0**: CVE-2026-85643 in
admin/adduser.php. - **Student Crud Operation 1.0**: CVE-2026-86518 in
/edit.php.
Several instances of information disclosure vulnerabilities were also identified, mostly related to backup file handlers:
- **Student Crud Operation 1.0**: CVE-2026-86519 in
/card_activation.sql. - **Hospital Information System 1.0**: CVE-2026-86302 in
/HIS/his.sql. - **Hotel and Tourism Reservation in PHP 1.0**: CVE-2026-86217 in
/ht/hotel_db%20(1).sql. - **Daily Expense Manager 1.0**: CVE-2026-86179 in
/Daily-Expense-Manager/exp_ak.sql. - **Vehicle Management System 1.0**: CVE-2026-85517 in
/vehicle_management.sql.
Additionally, cross-site scripting (XSS) vulnerabilities were found in:
- **Hospital Information System 1.0**: CVE-2026-86301 in
/HIS/src/patients/editPatient.php. - **Hotel and Tourism Reservation in PHP 1.0**: CVE-2026-86216 in
/ht/details.php. - **Task Management System 1.0**: CVE-2026-86181 in
/user/UpdateUserProfile.php.
According to related reporting from Vypr Intelligence, six high-severity SQL injection vulnerabilities affecting the Doctor Appointment System and Hospital Information System (CVE-2026-85225, CVE-2026-85397, CVE-2026-85398, CVE-2026-85399, CVE-2026-85402, CVE-2026-85403) were disclosed on September 4, 2026. Exploits for these specific flaws are publicly available, increasing the immediate risk to users of these systems.
The majority of these vulnerabilities, particularly the SQL injection flaws, are remotely exploitable and have publicly available exploits, indicating a significant risk to users who have not yet updated their systems. The affected applications are typically version 1.0. While specific patch details for each CVE are not provided in the batch, the reporting suggests that patches are available for the Doctor Appointment System and Hospital Information System. Users are strongly advised to consult vendor advisories for specific version information and apply updates promptly.
This large batch of vulnerabilities underscores the importance of regular security audits and timely patching for Code Projects applications. The widespread nature of these flaws, affecting multiple products and including critical vulnerabilities with public exploits, necessitates immediate attention from system administrators and users to mitigate potential security risks.
CVE-2026-86519, CVE-2026-86518, CVE-2026-86302, CVE-2026-86301, CVE-2026-86217, CVE-2026-86216, CVE-2026-86180, CVE-2026-86179, CVE-2026-86181, CVE-2026-86168, CVE-2026-85643, CVE-2026-85517, CVE-2026-85516, CVE-2026-85403, CVE-2026-85402, CVE-2026-85399, CVE-2026-85398, CVE-2026-85397, CVE-2026-85225