VYPR

Vendor CVEs

Dasinfomedia

All CVEs

34 total · sorted by risk
  • CVE-2025-47663CriMay 23, 2025
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System allows Upload a Web Shell to a Web Server. This issue affects Hospital Management System: from 47.0(20 through 11.

  • CVE-2017-14848HigOct 3, 2017
    risk 0.60cvss 8.8epss 0.03

    WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter.

  • CVE-2017-14847HigSep 28, 2017
    risk 0.60cvss 8.8epss 0.03

    Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.

  • CVE-2017-14846HigSep 28, 2017
    risk 0.60cvss 8.8epss 0.03

    Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.

  • CVE-2017-14845HigSep 28, 2017
    risk 0.60cvss 8.8epss 0.03

    Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.

  • CVE-2017-14844HigSep 28, 2017
    risk 0.60cvss 8.8epss 0.03

    Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.

  • CVE-2017-14843HigSep 28, 2017
    risk 0.60cvss 8.8epss 0.03

    Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.

  • CVE-2017-14842HigSep 28, 2017
    risk 0.60cvss 8.8epss 0.03

    Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter.

  • CVE-2025-47631HigMay 23, 2025
    risk 0.57cvss 8.8epss 0.00

    Incorrect Privilege Assignment vulnerability in mojoomla Hospital Management System allows Privilege Escalation. This issue affects Hospital Management System: from 47.0(20 through 11.

  • CVE-2025-11661HigOct 13, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This affects an unknown part. Performing manipulation results in missing authentication. The attack is possible to be carried out remotely. The exploit has…

  • CVE-2025-11660HigOct 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected by this issue is some unknown functionality of the file /assets/uploadSllyabus.php. Such manipulation of the argument File leads to…

  • CVE-2025-11659HigOct 13, 2025
    risk 0.47cvss 7.3epss 0.01

    A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected by this vulnerability is an unknown functionality of the file /assets/uploadNotes.php. This manipulation of the argument File causes unrestricted…

  • CVE-2025-11658HigOct 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected is an unknown function of the file /assets/changeSllyabus.php. The manipulation of the argument File results in unrestricted upload. The attack…

  • CVE-2025-11657HigOct 13, 2025
    risk 0.47cvss 7.3epss 0.01

    A security vulnerability has been detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This impacts an unknown function of the file /assets/createNotice.php. The manipulation of the argument File leads to unrestricted upload.…

  • CVE-2025-11656HigOct 13, 2025
    risk 0.47cvss 7.3epss 0.01

    A weakness has been identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This affects an unknown function of the file /assets/editNotes.php. Executing manipulation of the argument File can lead to unrestricted upload. The…

  • CVE-2017-14841MedSep 28, 2017
    risk 0.45cvss 6.5epss 0.02

    Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling.

  • CVE-2026-5472MedApr 3, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. The affected element is an unknown function of the file /admin_panel/settings.php of the component Profile Picture Handler. This manipulation of the argument…

  • CVE-2025-11056MedSep 27, 2025
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in ProjectsAndPrograms School Management System 1.0. Affected by this vulnerability is an unknown functionality of the file owner_panel/fetch-data/select-students.php. This manipulation of the argument select causes sql injection. Remote exploitation of the…

  • CVE-2026-4991LowMar 27, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in QDOCS Smart School Management System up to 7.2. The impacted element is an unknown function of the file /admin/enquiry of the component Admission Enquiry Module. Performing a manipulation of the argument Note results in cross site scripting. The…

  • CVE-2025-13795LowNov 30, 2025
    risk 0.16cvss 2.4epss 0.00

    A weakness has been identified in codingWithElias School Management System up to f1ac334bfd89ae9067cc14dea12ec6ff3f078c01. Affected is an unknown function of the file /student-view.php of the component Edit Student Info Page. This manipulation of the argument First Name causes…

  • CVE-2024-9659Nov 23, 2024
    risk 0.02cvss epss 0.02

    The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_user_avatar_image_upload() function in all versions up to, and including, 91.5.0. This makes it possible for unauthenticated…

  • CVE-2025-60500Oct 21, 2025
    risk 0.00cvss epss 0.00

    QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in the media upload feature by abusing the alternate YouTube URL option. This logic flaw permits uploading of arbitrary PHP files,…

  • CVE-2025-51967Aug 28, 2025
    risk 0.00cvss epss 0.00

    A Reflected Cross-site Scripting (XSS) vulnerability exists in the themeSet.php file of ProjectsAndPrograms School Management System 1.0. The application fails to sanitize user-supplied input in the theme POST parameter, allowing an attacker to inject and execute arbitrary…

  • CVE-2023-41530Aug 7, 2025
    risk 0.00cvss epss 0.00

    Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php.

  • CVE-2025-52187Jul 30, 2025
    risk 0.00cvss epss 0.00

    GetProjectsIdea Create School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in my_profile_update_form1.php.

  • CVE-2024-9658Mar 7, 2025
    risk 0.00cvss epss 0.00

    The School Management System for Wordpress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 93.0.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email…

  • CVE-2024-12609Mar 7, 2025
    risk 0.00cvss epss 0.00

    The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'view-attendance' page in all versions up to, and including, 92.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

  • CVE-2024-12610Mar 7, 2025
    risk 0.00cvss epss 0.00

    The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'mj_smgt_remove_feetype' and 'mj_smgt_remove_category_new' AJAX actions in all versions up to, and including, 93.0.0. This makes it…

  • CVE-2024-12611Mar 7, 2025
    risk 0.00cvss epss 0.00

    The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'title' parameter in all versions up to, and including, 93.0.0 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2024-12607Mar 7, 2025
    risk 0.00cvss epss 0.00

    The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'mj_smgt_show_event_task' AJAX action in all versions up to, and including, 92.0.0 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2024-9941Nov 23, 2024
    risk 0.00cvss epss 0.01

    The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the MJ_gmgt_add_staff_member() function in all versions up to, and including, 67.1.0. This makes it possible for authenticated attackers,…

  • CVE-2024-9942Nov 23, 2024
    risk 0.00cvss epss 0.01

    The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the MJ_gmgt_user_avatar_image_upload() function in all versions up to, and including, 67.1.0. This makes it possible for…

  • CVE-2024-9660Nov 23, 2024
    risk 0.00cvss epss 0.01

    The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the mj_smgt_load_documets_new() and mj_smgt_load_documets() functions in all versions up to, and including, 91.5.0. This makes it…

  • CVE-2020-36011Jan 26, 2021
    risk 0.00cvss epss 0.01

    A cross-site scripting (XSS) issue in Add Patient Form in QDOCS Smart Hospital Management System 3.1 allows a remote attacker to inject arbitrary code via the Name, Guardian Name, Email, Address, Remarks, or Any Known Allergies field.