CVE-2026-5644General

LOWCVSS 1.9 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security flaw has been discovered in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Affected is an unknown function of the file /admin/Add%20notice/batch-notice.php. Performing a manipulation of the argument $_SERVER['PHP_SELF'] results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-06: 3Technical Details · 2026-04-06: 104-06
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-5644 A security flaw has been discovered in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Affected is an unknown function of the file /… https://www.cve.org/CVERecord?id=CVE-2026-5644 ----- Traducción: CVE-2026-5644 Se … http://infoflow.cloud`

    Post summary

    The tweet reports the existence of CVE-2026-5644 in Cyber-III Student-Management-System with minimal details, providing only a CVE link and noting an unknown function is affected.

    0000032
    67 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5644 A security flaw has been discovered in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f. Affected is an unknown function of the file /… https://www.cve.org/CVERecord?id=CVE-2026-5644

    Post summary

    A CVE-2026-5644 flaw in Cyber-III Student-Management-System is noted, but no PoC, exploit, patch, or activity information is provided. The post merely references the CVE record without additional technical or operational details.

    00000475
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5644 Cross Site Scripting in Cyber-III Student-Management-System via PHP_SELF Manipulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5644

    Post summary

    CVE-2026-5644 is an XSS vulnerability in the Cyber-III Student-Management-System that exploits PHP_SELF manipulation. No evidence of exploitation or mitigation steps is mentioned.

    0000047
    4.0K followersView on X

Explore more