VYPR

Vendor CVEs

Itsourcecode

All CVEs

653 total · sorted by risk
  • CVE-2022-32380HigJun 15, 2022
    risk 0.47cvss 7.2epss 0.01

    itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_student_subject.php?index=.

  • CVE-2022-32379HigJun 15, 2022
    risk 0.47cvss 7.2epss 0.01

    itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_parents_profile.php?my_index=.

  • CVE-2022-32378HigJun 15, 2022
    risk 0.47cvss 7.2epss 0.01

    itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_teacher_profile.php?my_index=.

  • CVE-2022-32377HigJun 15, 2022
    risk 0.47cvss 7.2epss 0.01

    itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_exam_timetable.php?id=.

  • CVE-2022-32376HigJun 15, 2022
    risk 0.47cvss 7.2epss 0.01

    itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_events.php?event_id=.

  • CVE-2022-32375HigJun 15, 2022
    risk 0.47cvss 7.2epss 0.01

    itsourcecode Advanced School Management System v1.0 is vulnerable to SQL Injection via /school/model/get_timetable.php?id=.

  • CVE-2022-32351HigJun 14, 2022
    risk 0.47cvss 7.2epss 0.01

    Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_message.

  • CVE-2022-32343HigJun 14, 2022
    risk 0.47cvss 7.2epss 0.01

    Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via hprms/admin/room_types/manage_room_type.php?id=.

  • CVE-2025-25875MedFeb 21, 2025
    risk 0.42cvss 6.4epss 0.00

    A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /message.php. The attack can use SQL injection to obtain sensitive data.

  • CVE-2026-19934MedAug 16, 2026
    risk 0.41cvss 6.3epss

    A vulnerability has been found in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /vieworder.php. The manipulation of the argument delid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been…

  • CVE-2026-19894MedAug 15, 2026
    risk 0.41cvss 6.3epss

    A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /viewmedicine.php. Performing a manipulation of the argument delid results in sql injection. The attack can be initiated remotely. The exploit has been…

  • CVE-2026-19767MedAug 14, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. Executing a manipulation of the argument delid can lead to sql injection. The attack may be performed from remote. The…

  • CVE-2026-19364MedAug 9, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /viewdoctorconsultancycharge.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out…

  • CVE-2026-19347MedAug 9, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /viewdoctor.php. Such manipulation of the argument delid leads to sql injection. The attack can be launched remotely. The exploit is publicly…

  • CVE-2026-19071MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /viewappointment.php. This manipulation of the argument delid causes sql injection. It is possible to initiate the attack remotely. The exploit has been published…

  • CVE-2026-19070MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewadmin.php. The manipulation of the argument delid results in sql injection. The attack may be performed from remote. The exploit is now public and may…

  • CVE-2026-19069MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /treatmentrecord.php. The manipulation of the argument editid leads to sql injection. The attack is possible to be carried out remotely. The…

  • CVE-2026-19068MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /treatmentdetail.php. Executing a manipulation of the argument patientid can lead to sql injection. The attack can be executed remotely. The…

  • CVE-2026-19067MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /treatment.php. Performing a manipulation of the argument editid results in sql injection. Remote exploitation of the attack is possible.…

  • CVE-2026-19020MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /servicetype.php. This manipulation of the argument editid causes sql injection. It is possible to initiate the attack remotely.…

  • CVE-2026-11514MedJun 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /addpatient.php. This manipulation of the argument admissiontme causes sql injection. The attack may be initiated remotely. The exploit has been…

  • CVE-2026-11513MedJun 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /adminaccount.php. The manipulation of the argument Date results in sql injection. The attack can be launched remotely. The exploit is now public and may be…

  • CVE-2026-10811MedJun 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in itsourcecode Fees Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /receipt.php. Such manipulation of the argument ef_id leads to sql injection. The attack may be performed from remote.…

  • CVE-2026-10809MedJun 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in itsourcecode Fees Management System 1.0. This impacts an unknown function of the file /manage_user.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the…

  • CVE-2026-10808MedJun 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown function of the file /manage_student.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly…

  • CVE-2026-10568MedJun 2, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in itsourcecode Fees Management System 1.0. Affected is an unknown function of the file /manage_payment.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.

  • CVE-2026-10302MedJun 2, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in itsourcecode Fees Management System 1.0. The impacted element is an unknown function of the file /manage_fee.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published…

  • CVE-2026-10297MedJun 1, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown part of the file /manage_course.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available…

  • CVE-2026-10296MedJun 1, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in itsourcecode Fees Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The…

  • CVE-2026-10265MedJun 1, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in itsourcecode Content Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/edit_topic.php. Such manipulation of the argument topic_id leads to sql injection. The attack may be launched remotely. The…

  • CVE-2026-10258MedJun 1, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in itsourcecode Content Management System 1.0. Impacted is an unknown function of the file /admin/add_sub_topic.php. This manipulation of the argument topic_id causes sql injection. The attack is possible to be carried out remotely. The exploit has…

  • CVE-2026-10257MedJun 1, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in itsourcecode Content Management System 1.0. This issue affects some unknown processing of the file /admin/update_ss_img.php. The manipulation of the argument topic_id results in sql injection. The attack can be executed remotely. The…

  • CVE-2026-10256MedJun 1, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /save_comment.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit is…

  • CVE-2026-10242MedJun 1, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in itsourcecode Content Management System 1.0. This impacts an unknown function of the file /instructions.php. This manipulation of the argument topic_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2026-9607MedMay 27, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /parcel_list.php. Performing a manipulation of the argument s results in sql injection. It is possible to initiate the attack remotely. The exploit…

  • CVE-2026-7822MedMay 5, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in itsourcecode Courier Management System 1.0. This impacts an unknown function of the file /print_pdets.php. The manipulation of the argument ids leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and…

  • CVE-2026-6191MedApr 13, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /equipments.php. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched remotely. The exploit has been…

  • CVE-2026-6190MedApr 13, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /employees.php. Performing a manipulation of the argument Name results in sql injection. The attack can be initiated remotely. The exploit has…

  • CVE-2026-6030MedApr 10, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /del1.php. This manipulation of the argument toolname causes sql injection. Remote exploitation of the attack is possible. The exploit has been…

  • CVE-2026-6007MedApr 10, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /del.php. The manipulation of the argument equipname results in sql injection. The attack can be launched remotely. The exploit has been made public and…

  • CVE-2026-5823MedApr 9, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in itsourcecode Construction Management System 1.0. Affected by this issue is some unknown functionality of the file /borrowed_tool_report.php. This manipulation of the argument Home causes sql injection. It is possible to initiate the attack…

  • CVE-2026-5719MedApr 7, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /borrowedtool.php. Executing a manipulation of the argument code can lead to sql injection. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2026-5681MedApr 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in itsourcecode sanitize or validate this input 1.0. This impacts an unknown function of the file /borrowedequip.php of the component Parameter Handler. This manipulation of the argument emp_id causes sql injection. The attack is possible to be carried out…

  • CVE-2026-5675MedApr 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown part of the file /borrowed_tool.php of the component Parameter Handler. The manipulation of the argument emp results in sql injection. It is possible to launch the attack…

  • CVE-2026-5660MedApr 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in itsourcecode Construction Management System 1.0. The impacted element is an unknown function of the file /borrowed_equip.php of the component Parameter Handler. This manipulation of the argument emp causes sql injection. The attack may be…

  • CVE-2026-5620MedApr 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in itsourcecode Construction Management System 1.0. Affected is an unknown function of the file /borrowed_equip_report.php of the component Parameter Handler. The manipulation of the argument Home leads to sql injection. It is possible to initiate…

  • CVE-2026-5553MedApr 5, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in itsourcecode Online Cellphone System 1.0. Affected by this vulnerability is an unknown functionality of the file /cp/available.php of the component Parameter Handler. Such manipulation of the argument Name leads to sql injection. The attack can…

  • CVE-2026-4966MedMar 27, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in itsourcecode Free Hotel Reservation System 1.0. Impacted is an unknown function of the file /admin/mod_room/index.php?view=edit. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has…

  • CVE-2026-4876MedMar 26, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in itsourcecode Free Hotel Reservation System 1.0. The impacted element is an unknown function of the file /admin/mod_amenities/index.php?view=editpic. Such manipulation of the argument ID leads to sql injection. The attack may be performed from…

  • CVE-2026-4783MedMar 25, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in itsourcecode College Management System 1.0. The impacted element is an unknown function of the file /admin/add-single-student-results.php of the component Parameter Handler. The manipulation of the argument course_code leads to sql injection. It…

Page 8 of 14