VYPR

Vendor CVEs

Campcodes

All CVEs

664 total · sorted by risk
  • CVE-2023-39115CriAug 16, 2023
    risk 0.67cvss 9.8epss 0.08

    install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document.

  • CVE-2024-41551CriJul 24, 2024
    risk 0.64cvss 9.8epss 0.00

    CampCodes Supplier Management System v1.0 is vulnerable to SQL injection via Supply_Management_System/admin/view_order_items.php?id= .

  • CVE-2024-33808CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /model/get_timetable.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.

  • CVE-2024-33806CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /model/get_grade.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.

  • CVE-2024-33805CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /model/get_student.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.

  • CVE-2024-33801CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /model/get_subject_routing.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.

  • CVE-2024-33800CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /model/get_student1.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the index parameter.

  • CVE-2024-33799CriMay 28, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /model/get_teacher.php in campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the id parameter.

  • CVE-2024-34935CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /view/conversation_history_admin.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id parameter.

  • CVE-2024-34934CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /view/emarks_range_grade_update_form.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the conversation_id parameter.

  • CVE-2024-34932CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /model/update_exam.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.

  • CVE-2024-34931CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /model/update_subject.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.

  • CVE-2024-34929CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /view/find_friends.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the my_index parameter.

  • CVE-2024-34927CriMay 23, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /model/update_classroom.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the name parameter.

  • CVE-2024-33411CriMay 6, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /model/get_admin_profile.php in Campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the my_index parameter.

  • CVE-2024-33409CriMay 6, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in index.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the name parameter.

  • CVE-2024-33408CriMay 6, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /model/get_classroom.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.

  • CVE-2024-33403CriMay 6, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability in /model/get_events.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the event_id parameter.

  • CVE-2022-32019CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.02

    Car Rental Management System v1.0 is vulnerable to Arbitrary code execution via car-rental-management-system/admin/ajax.php?action=save_car.

  • CVE-2022-32020CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.02

    Car Rental Management System v1.0 is vulnerable to Arbitrary code execution via ip/car-rental-management-system/admin/ajax.php?action=save_settings.

  • CVE-2022-26171CriMar 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Bank Management System v1.o was discovered to contain a SQL injection vulnerability via the email parameter.

  • CVE-2024-34936HigMay 23, 2024
    risk 0.56cvss 8.6epss 0.00

    A SQL injection vulnerability in /view/event1.php in Campcodes Complete Web-Based School Management System 1.0 allows an attacker to execute arbitrary SQL commands via the month parameter.

  • CVE-2024-33405HigMay 6, 2024
    risk 0.56cvss 8.6epss 0.01

    SQL injection vulnerability in add_friends.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the friend_index parameter.

  • CVE-2024-33404HigMay 6, 2024
    risk 0.54cvss 8.3epss 0.01

    A SQL injection vulnerability in /model/add_student_first_payment.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the index parameter.

  • CVE-2024-33402HigMay 28, 2024
    risk 0.53cvss 8.1epss 0.00

    A SQL injection vulnerability in /model/approve_petty_cash.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.

  • CVE-2024-33410HigMay 6, 2024
    risk 0.53cvss 8.1epss 0.01

    SQL injection vulnerability in /model/delete_range_grade.php in campcodes Complete Web-Based School Management System 1.0 allows attacker to execute arbitrary SQL commands via the id parameter.

  • CVE-2025-5298HigMay 28, 2025
    risk 0.51cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affected is an unknown function of the file /admin/betweendates-detailsreports.php. The manipulation of the argument fromdate/todate leads to sql injection. It is…

  • CVE-2025-10810HigSep 22, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was detected in Campcodes Online Learning Management System 1.0. The impacted element is an unknown function of the file /admin/edit_user.php. Performing manipulation of the argument firstname results in sql injection. The attack is possible to be carried out…

  • CVE-2025-9744HigAug 31, 2025
    risk 0.48cvss 7.3epss 0.02

    A weakness has been identified in Campcodes Online Loan Management System 1.0. The affected element is an unknown function of the file /ajax.php?action=login. Executing manipulation of the argument Username can lead to sql injection. The attack can be launched remotely. The…

  • CVE-2025-6403HigJun 21, 2025
    risk 0.48cvss 7.3epss 0.02

    A vulnerability was found in code-projects School Fees Payment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /student.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The…

  • CVE-2024-7219HigJul 30, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in SourceCodester/Campcodes School Log Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login. The manipulation of the argument Username leads to sql injection. It is possible to…

  • CVE-2024-3535HigApr 10, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in Campcodes Church Management System 1.0. This affects an unknown part of the file /admin/index.php. The manipulation of the argument password leads to sql injection. It is possible to initiate the attack remotely.…

  • CVE-2024-3534HigApr 10, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in Campcodes Church Management System 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument password leads to sql injection. The attack may be launched…

  • CVE-2024-3226HigApr 3, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Campcodes Online Patient Record Management System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/login.php. The manipulation of the argument password leads to sql injection. It is possible to initiate the…

  • CVE-2024-2916HigMar 26, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Campcodes House Rental Management System 1.0. It has been classified as critical. Affected is an unknown function of the file ajax.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely.…

  • CVE-2023-7156HigDec 29, 2023
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in Campcodes Online College Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file index.php of the component Search. The manipulation of the argument category leads to sql injection. The attack can be…

  • CVE-2023-3873HigJul 25, 2023
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in Campcodes Beauty Salon Management System 1.0. This issue affects some unknown processing of the file /admin/index.php. The manipulation of the argument username leads to sql injection. The attack may be…

  • CVE-2023-2073HigApr 14, 2023
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Campcodes Online Traffic Offense Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /classes/Login.php. The manipulation of the argument password leads to sql injection. The…

  • CVE-2025-15207HigDec 29, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/view_products.php. The manipulation of the argument chkId[] leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2025-15206HigDec 29, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /admin/add_area.php. Executing a manipulation of the argument txtAreaCode can lead to sql injection. The attack may be performed from remote. The exploit has been…

  • CVE-2025-14990HigDec 21, 2025
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in Campcodes Complete Online Beauty Parlor Management System 1.0. Impacted is an unknown function of the file /admin/view-appointment.php. Performing a manipulation of the argument viewid results in sql injection. The attack may be initiated…

  • CVE-2025-14989HigDec 21, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This issue affects some unknown processing of the file /admin/search-invoices.php. Such manipulation leads to sql injection. The attack can be launched remotely. The exploit is…

  • CVE-2025-14952HigDec 19, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_category.php. Performing a manipulation of the argument txtCategoryName results in sql injection. The attack is possible to be carried out remotely.…

  • CVE-2025-14877HigDec 18, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_retailer.php. The manipulation of the argument cmbAreaCode leads to sql injection. The attack is possible to be carried out remotely. The exploit…

  • CVE-2025-14668HigDec 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in campcodes Advanced Online Examination System 1.0. This affects an unknown function of the file /query/loginExe.php. Performing a manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely. The…

  • CVE-2025-14664HigDec 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in Campcodes Supplier Management System 1.0. This issue affects some unknown processing of the file /admin/view_unit.php. The manipulation of the argument chkId[] leads to sql injection. Remote exploitation of the attack is possible. The exploit is…

  • CVE-2025-14583HigDec 12, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in campcodes Online Student Enrollment System 1.0. This impacts an unknown function of the file /admin/register.php. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack can be launched remotely. The exploit has been…

  • CVE-2025-14529HigDec 11, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The affected element is an unknown function of the file /admin/admin_running.php. This manipulation of the argument pid causes sql injection. It is possible to initiate the attack remotely. The exploit…

  • CVE-2025-14515HigDec 11, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add_unit.php. Such manipulation of the argument txtunitDetails leads to sql injection. The attack can be launched remotely.…

  • CVE-2025-14514HigDec 11, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/add_distributor.php. This manipulation of the argument txtDistributorAddress causes sql injection. The attack can be initiated remotely. The exploit has been…

Page 1 of 14