CVE-2026-3756Disclosure(ahsanriaz26gmailcom / sales_and_inventory_system)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in SourceCodester Sales and Inventory System up to 1.0. Affected is an unknown function of the file /check_item_details.php. The manipulation of the argument stock_name1 leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sales_and_inventory_system

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-08); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Products
sales_and_inventory_system

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-03-08: 2Mentions · 2026-03-09: 2Technical Details · 2026-03-08: 2Technical Details · 2026-03-09: 103-0803-09
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • DailyCVE@dailycve
    Disclosure

    🟠 SourceCodester Sales and Inventory System, SQL Injection, #CVE-2026-3756 (Medium) https://dailycve.com/sourcecodester-sales-and-inventory-system-sql-injection-cve-2026-3756-medium/

    Post summary

    The post announces a Medium‑severity SQL injection flaw (CVE‑2026‑3756) in SourceCodester's Sales and Inventory System and links to a DailyCVE article for details.

    0000029
    166 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-3756 - SourceCodester - Sales and Inventory System - https://www.redpacketsecurity.com/cve-alert-cve-2026-3756-sourcecodester-sales-and-inventory-system/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3756 #sourcecodester #sales-and-inventory-system

    Post summary

    The post serves as a brief announcement of CVE-2026-3756 affecting SourceCodester Sales and Inventory System, linking to a security alert page but providing no technical or exploitation details.

    0000082
    3.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3756 A vulnerability was identified in SourceCodester Sales and Inventory System up to 1.0. Affected is an unknown function of the file /check_item_details.php. The manipula… https://www.cve.org/CVERecord?id=CVE-2026-3756

    Post summary

    A new CVE-2026-3756 vulnerability was disclosed in SourceCodester Sales and Inventory System, affecting the /check_item_details.php file; technical details are provided, but no PoC, exploit code, patch, or active exploitation information is offered.

    0000071
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3756 SQL Injection in SourceCodester Sales and Inventory System via stock_name1 Argument https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3756

    Post summary

    The post announces CVE-2026-3756, an SQL injection flaw in SourceCodester Sales and Inventory System via the stock_name1 argument.

    0000040
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appahsanriaz26gmailcomsales_and_inventory_system1.0--

Explore more