OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-95925

HIGH · CVSS 7.3 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The SourceCodester Online Reviewer Management System 1.0 is vulnerable to SQL injection through the `difficulty_id` parameter in the `btn_functions.php` file, allowing remote attackers to manipulate database queries. This could lead to unauthorized data access or modification, posing a significant risk to the integrity of the system. Organizations using this software should prioritize patching this vulnerability to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-95925
Severity
HIGH
CVSS
7.3
EPSS
0.27%

Original NVD Description

A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=update. The manipulation of the argument difficulty_id results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.