Vendor CVEs
Lan Management System
All CVEs
71 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-44755 | Cri | 0.64 | 9.8 | 0.01 | Apr 22, 2025 | Sacco Management system v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /sacco/ajax.php. | ||
| CVE-2024-28613 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2024 | SQL Injection vulnerability in PHP Task Management System v.1.0 allows a remote attacker to escalate privileges and obtain sensitive information via the task_id parameter of the task-details.php, and edit-task.php component. | ||
| CVE-2023-49543 | Cri | 0.64 | 9.8 | 0.01 | Mar 1, 2024 | Incorrect access control in Book Store Management System v1 allows attackers to access unauthorized pages and execute administrative functions without authenticating. | ||
| CVE-2023-51951 | Cri | 0.64 | 9.8 | 0.01 | Feb 5, 2024 | SQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id parameter in the manage_bo.php file. | ||
| CVE-2023-30245 | Cri | 0.64 | 9.8 | 0.01 | May 15, 2023 | SQL injection vulnerability found in Judging Management System v.1.0 allows a remote attacker to execute arbitrary code via the crit_id parameter of the edit_criteria.php file. | ||
| CVE-2023-30018 | Cri | 0.64 | 9.8 | 0.01 | May 8, 2023 | Judging Management System v1.0 is vulnerable to SQL Injection. via /php-jms/review_se_result.php?mainevent_id=. | ||
| CVE-2023-24643 | Cri | 0.64 | 9.8 | 0.01 | Mar 3, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateBlankTxtview.php. | ||
| CVE-2023-24642 | Cri | 0.64 | 9.8 | 0.01 | Mar 3, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateTxtview.php. | ||
| CVE-2023-24641 | Cri | 0.64 | 9.8 | 0.01 | Mar 3, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateview.php. | ||
| CVE-2023-23279 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | Canteen Management System 1.0 is vulnerable to SQL Injection via /php_action/getOrderReport.php. | ||
| CVE-2022-35156 | Cri | 0.64 | 9.8 | 0.01 | Sep 30, 2022 | Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php.. | ||
| CVE-2022-34023 | Cri | 0.64 | 9.8 | 0.01 | Jul 19, 2022 | Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /officials/officials.php. | ||
| CVE-2022-30370 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo_type. | ||
| CVE-2022-29656 | Cri | 0.64 | 9.8 | 0.01 | May 11, 2022 | Wedding Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Wedding-Management/package_detail.php. | ||
| CVE-2020-23621 | Cri | 0.64 | 9.8 | 0.02 | May 2, 2022 | The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object. | ||
| CVE-2021-45003 | Cri | 0.64 | 9.8 | 0.03 | Jan 10, 2022 | Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.php through the "image" parameter that can execute a webshell payload. | ||
| CVE-2024-48594 | Hig | 0.60 | 8.8 | 0.03 | Oct 28, 2024 | File Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the file upload component. | ||
| CVE-2023-53734 | Hig | 0.57 | — | 0.01 | Dec 4, 2025 | dawa-pharma-1.0 allows unauthenticated attackers to execute SQL queries on the server, allowing them to access sensitive information and potentially gain administrative access. | ||
| CVE-2020-36073 | Hig | 0.57 | 8.8 | 0.01 | Apr 6, 2023 | SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via the detail parameter of the document.php page. | ||
| CVE-2020-36072 | Hig | 0.57 | 8.8 | 0.01 | Apr 6, 2023 | SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via the id parameter. | ||
| CVE-2020-36071 | Hig | 0.57 | 8.8 | 0.01 | Apr 6, 2023 | SQL injection vulnerability found in Tailor Management System v.1 allows a remote authenticated attacker to execute arbitrary code via the customer parameter of the email.php page. | ||
| CVE-2022-32396 | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/manage_visit.php:4 | ||
| CVE-2022-32395 | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/manage_crime.php:4 | ||
| CVE-2022-32393 | Hig | 0.57 | 8.8 | 0.01 | Jun 24, 2022 | Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/view_cell.php:4 | ||
| CVE-2024-31502 | Hig | 0.53 | 8.1 | 0.01 | Apr 26, 2024 | An issue in Insurance Management System v.1.0.0 and before allows a remote attacker to escalate privileges via a crafted POST request to /admin/core/new_staff. | ||
| CVE-2023-44824 | Hig | 0.51 | 7.8 | 0.00 | Oct 17, 2023 | An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploaded to the sign-up.php component. | ||
| CVE-2018-1000535 | Hig | 0.49 | 7.5 | 0.02 | Jun 26, 2018 | lms version <= LMS_011123 contains a Local File Disclosure vulnerability in File reading functionality in LMS module that can result in Possible to read files on the server. This attack appear to be exploitable via GET parameter. This vulnerability appears to have been fixed in… | ||
| CVE-2023-31937 | Hig | 0.47 | 7.2 | 0.01 | Jul 28, 2023 | Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the editid parameter of the edit-cateogry-detail.php file. | ||
| CVE-2022-43146 | Hig | 0.47 | 7.2 | 0.01 | Nov 14, 2022 | An arbitrary file upload vulnerability in the image upload function of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-41406 | Hig | 0.47 | 7.2 | 0.01 | Oct 12, 2022 | An arbitrary file upload vulnerability in the /admin/admin_pic.php component of Church Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-40932 | Hig | 0.47 | 7.2 | 0.01 | Sep 22, 2022 | In Zoo Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of the "gallery" file of the "Gallery" module in the background management system. | ||
| CVE-2022-38595 | Hig | 0.47 | 7.2 | 0.01 | Sep 15, 2022 | Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_user.php. | ||
| CVE-2022-38594 | Hig | 0.47 | 7.2 | 0.01 | Sep 15, 2022 | Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_visitor.php. | ||
| CVE-2022-38605 | Hig | 0.47 | 7.2 | 0.01 | Sep 12, 2022 | Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_event.php. | ||
| CVE-2022-36754 | Hig | 0.47 | 7.2 | 0.01 | Sep 2, 2022 | Expense Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Home/debit_credit_p. | ||
| CVE-2022-36582 | Hig | 0.47 | 7.2 | 0.01 | Aug 31, 2022 | An arbitrary file upload vulnerability in the component /php_action/createProduct.php of Garage Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-29655 | Hig | 0.47 | 7.2 | 0.01 | May 11, 2022 | An arbitrary file upload vulnerability in the Upload Photos module of Wedding Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2024-25325 | Hig | 0.46 | 7.1 | 0.00 | Mar 12, 2024 | SQL injection vulnerability in Employee Management System v.1.0 allows a local attacker to obtain sensitive information via a crafted payload to the txtemail parameter in the login.php. | ||
| CVE-2025-29456 | Med | 0.42 | 6.5 | 0.00 | Apr 17, 2025 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the create Notes function. | ||
| CVE-2025-29453 | Med | 0.42 | 6.5 | 0.00 | Apr 17, 2025 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the my-contacts-settings component. | ||
| CVE-2025-29455 | Med | 0.42 | 6.5 | 0.00 | Apr 17, 2025 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Ideas" function. | ||
| CVE-2025-29454 | Med | 0.42 | 6.5 | 0.00 | Apr 17, 2025 | An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Upload function. | ||
| CVE-2022-29008 | Med | 0.42 | 6.5 | 0.01 | May 11, 2022 | An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensitive information. | ||
| CVE-2025-70890 | Med | 0.40 | 6.1 | 0.00 | Jan 15, 2026 | A stored cross-site scripting (XSS) vulnerability exists in Cyber Cafe Management System v1.0. An authenticated attacker can inject arbitrary JavaScript code into the username parameter via the add-users.php endpoint. The injected payload is stored and executed in the victim s… | ||
| CVE-2024-31648 | Med | 0.40 | 6.1 | 0.00 | Apr 15, 2024 | Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter at /core/new_category2. | ||
| CVE-2023-49540 | Med | 0.40 | 6.1 | 0.01 | Mar 1, 2024 | Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/history. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the history parameter. | ||
| CVE-2023-49539 | Med | 0.40 | 6.1 | 0.01 | Mar 1, 2024 | Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/category. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the category parameter. | ||
| CVE-2023-23024 | Med | 0.40 | 6.1 | 0.00 | Jan 20, 2023 | Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the writer parameter. | ||
| CVE-2022-46622 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2023 | A cross-site scripting (XSS) vulnerability in Judging Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter. | ||
| CVE-2022-45225 | Med | 0.40 | 6.1 | 0.00 | Nov 25, 2022 | Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the book_title parameter. |
- risk 0.64cvss 9.8epss 0.01
Sacco Management system v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /sacco/ajax.php.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in PHP Task Management System v.1.0 allows a remote attacker to escalate privileges and obtain sensitive information via the task_id parameter of the task-details.php, and edit-task.php component.
- risk 0.64cvss 9.8epss 0.01
Incorrect access control in Book Store Management System v1 allows attackers to access unauthorized pages and execute administrative functions without authenticating.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id parameter in the manage_bo.php file.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability found in Judging Management System v.1.0 allows a remote attacker to execute arbitrary code via the crit_id parameter of the edit_criteria.php file.
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 is vulnerable to SQL Injection. via /php-jms/review_se_result.php?mainevent_id=.
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateBlankTxtview.php.
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateTxtview.php.
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the sid parameter at /php-jms/updateview.php.
- risk 0.64cvss 9.8epss 0.01
Canteen Management System 1.0 is vulnerable to SQL Injection via /php_action/getOrderReport.php.
- risk 0.64cvss 9.8epss 0.01
Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..
- risk 0.64cvss 9.8epss 0.01
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /officials/officials.php.
- risk 0.64cvss 9.8epss 0.01
Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo_type.
- risk 0.64cvss 9.8epss 0.01
Wedding Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Wedding-Management/package_detail.php.
- risk 0.64cvss 9.8epss 0.02
The Java Remote Management Interface of all versions of SVI MS Management System was discovered to contain a vulnerability due to insecure deserialization of user-supplied content, which can allow attackers to execute arbitrary code via a crafted serialized Java object.
- risk 0.64cvss 9.8epss 0.03
Laundry Booking Management System 1.0 (Latest) and previous versions are affected by a remote code execution (RCE) vulnerability in profile.php through the "image" parameter that can execute a webshell payload.
- risk 0.60cvss 8.8epss 0.03
File Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the file upload component.
- risk 0.57cvss —epss 0.01
dawa-pharma-1.0 allows unauthenticated attackers to execute SQL queries on the server, allowing them to access sensitive information and potentially gain administrative access.
- risk 0.57cvss 8.8epss 0.01
SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via the detail parameter of the document.php page.
- risk 0.57cvss 8.8epss 0.01
SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via the id parameter.
- risk 0.57cvss 8.8epss 0.01
SQL injection vulnerability found in Tailor Management System v.1 allows a remote authenticated attacker to execute arbitrary code via the customer parameter of the email.php page.
- risk 0.57cvss 8.8epss 0.01
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/manage_visit.php:4
- risk 0.57cvss 8.8epss 0.01
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/manage_crime.php:4
- risk 0.57cvss 8.8epss 0.01
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/view_cell.php:4
- risk 0.53cvss 8.1epss 0.01
An issue in Insurance Management System v.1.0.0 and before allows a remote attacker to escalate privileges via a crafted POST request to /admin/core/new_staff.
- risk 0.51cvss 7.8epss 0.00
An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploaded to the sign-up.php component.
- risk 0.49cvss 7.5epss 0.02
lms version <= LMS_011123 contains a Local File Disclosure vulnerability in File reading functionality in LMS module that can result in Possible to read files on the server. This attack appear to be exploitable via GET parameter. This vulnerability appears to have been fixed in…
- risk 0.47cvss 7.2epss 0.01
Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the editid parameter of the edit-cateogry-detail.php file.
- risk 0.47cvss 7.2epss 0.01
An arbitrary file upload vulnerability in the image upload function of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.47cvss 7.2epss 0.01
An arbitrary file upload vulnerability in the /admin/admin_pic.php component of Church Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.47cvss 7.2epss 0.01
In Zoo Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of the "gallery" file of the "Gallery" module in the background management system.
- risk 0.47cvss 7.2epss 0.01
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_user.php.
- risk 0.47cvss 7.2epss 0.01
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_visitor.php.
- risk 0.47cvss 7.2epss 0.01
Church Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/edit_event.php.
- risk 0.47cvss 7.2epss 0.01
Expense Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Home/debit_credit_p.
- risk 0.47cvss 7.2epss 0.01
An arbitrary file upload vulnerability in the component /php_action/createProduct.php of Garage Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.47cvss 7.2epss 0.01
An arbitrary file upload vulnerability in the Upload Photos module of Wedding Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.46cvss 7.1epss 0.00
SQL injection vulnerability in Employee Management System v.1.0 allows a local attacker to obtain sensitive information via a crafted payload to the txtemail parameter in the login.php.
- risk 0.42cvss 6.5epss 0.00
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the create Notes function.
- risk 0.42cvss 6.5epss 0.00
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the my-contacts-settings component.
- risk 0.42cvss 6.5epss 0.00
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Ideas" function.
- risk 0.42cvss 6.5epss 0.00
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Upload function.
- risk 0.42cvss 6.5epss 0.01
An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensitive information.
- risk 0.40cvss 6.1epss 0.00
A stored cross-site scripting (XSS) vulnerability exists in Cyber Cafe Management System v1.0. An authenticated attacker can inject arbitrary JavaScript code into the username parameter via the add-users.php endpoint. The injected payload is stored and executed in the victim s…
- risk 0.40cvss 6.1epss 0.00
Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter at /core/new_category2.
- risk 0.40cvss 6.1epss 0.01
Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/history. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the history parameter.
- risk 0.40cvss 6.1epss 0.01
Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/category. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the category parameter.
- risk 0.40cvss 6.1epss 0.00
Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the writer parameter.
- risk 0.40cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability in Judging Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter.
- risk 0.40cvss 6.1epss 0.00
Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the book_title parameter.
Page 1 of 2