VYPR

Community Project Scholars Tracking System

by Code Projects

CVEs (7)

  • CVE-2025-70152CriFeb 18, 2026
    risk 0.64cvss 9.8epss 0.00

    code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly concatenate user-supplied POST parameters…

  • CVE-2024-24101CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.00

    Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update.

  • CVE-2024-24093CriMar 12, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Personal Information Update information.

  • CVE-2025-70151HigFeb 18, 2026
    risk 0.57cvss 8.8epss 0.01

    code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-accessible uploads/ directory using the…

  • CVE-2024-24098HigMar 5, 2024
    risk 0.51cvss 7.8epss 0.00

    Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection via the News Feed.

  • CVE-2024-24097MedMar 12, 2024
    risk 0.35cvss 5.4epss 0.00

    Cross Site Scripting (XSS) vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via the News Feed.

  • CVE-2024-24099MedFeb 27, 2024
    risk 0.35cvss 5.4epss 0.00

    Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Employment Status Information Update.