CVE-2026-85225
A vulnerability was identified in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient_login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
- Published Sep 3, 2026
- CVSS 5.5 medium
- 0.4% chance of exploitation in the next 30 days (EPSS)