A SQL injection vulnerability has been identified in code-projects Vehicle Management System 1.0. The vulnerability resides in an unknown function within the file /busprofile.php, where manipulation of the 'busid' argument allows for SQL injection attacks. The vulnerability can be exploited remotely without requiring physical access to the system. A public exploit is already available, increasing the risk of active exploitation. The affected product is a web-based vehicle management application. The vulnerability has been assigned CVE-2026-85516 and is tracked in VulDB as entry 398680. No patch or workaround details are mentioned in the article. Organizations using this software should take immediate action to mitigate exposure.