CVE List

CVE-2026-2158

Critical 7.3

A vulnerability was detected in code-projects Student Web Portal 1.0. This impacts an unknown function of the file /check_user.php. Performing a manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely.

Published February 8, 2026.

Affected software

Get alerts for Carmelo Student Web Portal

Reference links