VYPR

Simple Online Leave Management System

by Codeastro

CVEs (6)

  • CVE-2026-8132HigMay 8, 2026
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /login.php. This manipulation of the argument txt_username causes sql injection. The attack can be initiated remotely. The exploit has been made available to the…

  • CVE-2026-9542MedMay 26, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php. Executing a manipulation of the argument email_id can lead to sql injection. The attack can be launched remotely. The exploit…

  • CVE-2026-15559MedJul 13, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was detected in CodeAstro Simple Online Leave Management System 1.0. This affects an unknown part of the file /SimpleOnlineLeave/admin/accept.php of the component POST Handler. Performing a manipulation of the argument appid results in sql injection. The attack…

  • CVE-2026-15558MedJul 13, 2026
    risk 0.00cvss 6.3epss 0.00

    A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/deletemp.php. Such manipulation of the argument ID leads to sql injection. The attack can…

  • CVE-2026-15523MedJul 13, 2026
    risk 0.00cvss 6.3epss 0.00

    A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/dashboard.php. This manipulation of the argument Name causes sql injection. The attack can be…

  • CVE-2026-15134HigJul 9, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was determined in CodeAstro Simple Online Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /SimpleOnlineLeave/index.php. Executing a manipulation of the argument email can lead to sql injection. The attack may be…