VYPR

Vendor CVEs

Oretnom23

All CVEs

1,064 total · sorted by risk
  • CVE-2025-40685MedJul 29, 2025
    risk 0.40cvss 6.1epss 0.00

    Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'searcstate' parameter in/state.php.

  • CVE-2025-40684MedJul 29, 2025
    risk 0.40cvss 6.1epss 0.00

    Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'searccountry' parameter in/country.php.

  • CVE-2025-40683MedJul 29, 2025
    risk 0.40cvss 6.1epss 0.00

    Reflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'searccity' parameter in /city.php.

  • CVE-2025-40729MedJun 16, 2025
    risk 0.40cvss 6.1epss 0.00

    Reflected Cross-Site Scripting (XSS) in /customer_support/index.php in Customer Support System v1.0, which allows remote attackers to execute arbitrary code via the page parameter.

  • CVE-2025-2870MedMar 28, 2025
    risk 0.40cvss 6.1epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in version 1.0 of the Clinic Queuing System. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the page parameter in /patient_side.php.

  • CVE-2025-2869MedMar 28, 2025
    risk 0.40cvss 6.1epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in version 1.0 of the Clinic Queuing System. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the id parameter in /manage_user.php.

  • CVE-2025-2868MedMar 28, 2025
    risk 0.40cvss 6.1epss 0.00

    Reflected Cross-Site Scripting (XSS) vulnerability in version 1.0 of the Clinic Queuing System. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the page parameter in /index.php.

  • CVE-2024-37859MedJul 29, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the page parameter to php-lfis/admin/index.php.

  • CVE-2024-31586MedJun 20, 2024
    risk 0.40cvss 6.1epss 0.00

    A Cross Site Scripting (XSS) vulnerability exists in Computer Laboratory Management System version 1.0. This vulnerability allows a remote attacker to execute arbitrary code via the Borrower Name, Department, and Remarks parameters.

  • CVE-2024-35583MedMay 28, 2024
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Remarks input field.

  • CVE-2024-35582MedMay 28, 2024
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Department input field.

  • CVE-2024-35581MedMay 28, 2024
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Borrower Name input field.

  • CVE-2024-34225MedMay 14, 2024
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the name, shortname parameters.

  • CVE-2024-33304MedMay 1, 2024
    risk 0.40cvss 6.1epss 0.00

    SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" under Add Users.

  • CVE-2023-23022MedMay 1, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross site scripting (XSS) vulnerability in sourcecodester oretnom23 employee's payroll management system 1.0, allows attackers to execute arbitrary code via the code, title, from_date and to_date inputs in file Main.php.

  • CVE-2023-23021MedMay 1, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting (XSS) vulnerability in sourcecodester oretnom23 pos point sale system 1.0, allows attackers to execute arbitrary code via the code, name, and description inputs in file Main.php.

  • CVE-2024-31651MedApr 15, 2024
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the First Name parameter.

  • CVE-2024-31652MedApr 15, 2024
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search parameter.

  • CVE-2023-49984MedMar 21, 2024
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) vulnerability in the component /management/settings of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.

  • CVE-2022-46089MedMar 7, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting (XSS) vulnerability in the add-airline form of Online Flight Booking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the airline parameter.

  • CVE-2023-49974MedMar 6, 2024
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the contact parameter at /customer_support/index.php?page=customer_list.

  • CVE-2023-49973MedMar 6, 2024
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter at /customer_support/index.php?page=customer_list.

  • CVE-2023-49971MedMar 6, 2024
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the firstname parameter at /customer_support/index.php?page=customer_list.

  • CVE-2022-46088MedMar 5, 2024
    risk 0.40cvss 6.1epss 0.00

    Online Flight Booking Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the feedback form.

  • CVE-2024-25551MedMar 3, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting (XSS) vulnerability in sourcecodester Simple Student Attendance System v1.0 allows attackers to execute arbitrary code via crafted GET request to web application URL.

  • CVE-2023-49540MedMar 1, 2024
    risk 0.40cvss 6.1epss 0.01

    Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/history. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the history parameter.

  • CVE-2023-49539MedMar 1, 2024
    risk 0.40cvss 6.1epss 0.01

    Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/category. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the category parameter.

  • CVE-2023-51802MedFeb 29, 2024
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the page or class_month parameter in the /php-attendance/attendance_report component.

  • CVE-2023-36159MedAug 4, 2023
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers to run arbitrary code via the First Name, Middle Name and Last Name fields on the Create User page.

  • CVE-2023-36158MedAug 4, 2023
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability in sourcecodester Toll Tax Management System 1.0 allows remote attackers to run arbitrary code via the First Name and Last Name fields on the My Account page.

  • CVE-2023-29623MedApr 14, 2023
    risk 0.40cvss 6.1epss 0.01

    Purchase Order Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the password parameter at /purchase_order/classes/login.php.

  • CVE-2023-24197MedFeb 6, 2023
    risk 0.40cvss 6.1epss 0.00

    Online Food Ordering System v2 was discovered to contain a SQL injection vulnerability via the id parameter at view_order.php.

  • CVE-2023-24195MedFeb 6, 2023
    risk 0.40cvss 6.1epss 0.00

    Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in index.php.

  • CVE-2023-24194MedFeb 6, 2023
    risk 0.40cvss 6.1epss 0.00

    Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in navbar.php.

  • CVE-2023-24192MedFeb 6, 2023
    risk 0.40cvss 6.1epss 0.00

    Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in login.php.

  • CVE-2023-24191MedFeb 6, 2023
    risk 0.40cvss 6.1epss 0.00

    Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in signup.php.

  • CVE-2022-45218MedNov 25, 2022
    risk 0.40cvss 6.1epss 0.00

    Human Resource Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability. This vulnerability is triggered via a crafted payload injected into an authentication error message.

  • CVE-2022-43317MedNov 7, 2022
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) vulnerability in /hrm/index.php?msg of Human Resource Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2022-42071MedOct 14, 2022
    risk 0.40cvss 6.1epss 0.00

    Online Birth Certificate Management System version 1.0 suffers from a Cross Site Scripting (XSS) Vulnerability.

  • CVE-2022-36251MedAug 22, 2022
    risk 0.40cvss 6.1epss 0.01

    Clinic's Patient Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via patients.php.

  • CVE-2022-26644MedMar 30, 2022
    risk 0.40cvss 6.1epss 0.01

    Online Banking System Protect v1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via parameters on user profile, system_info and accounts management.

  • CVE-2021-43141MedNov 3, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Simple Subscription Website 1.0 via the id parameter in plan_application.

  • CVE-2024-40068MedApr 16, 2025
    risk 0.38cvss 5.9epss 0.00

    Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=templates/manage_template&id=1.

  • CVE-2024-34222MedMay 14, 2024
    risk 0.38cvss 5.9epss 0.00

    Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.

  • CVE-2024-3466MedApr 8, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been declared as critical. Affected by this vulnerability is the function laporan_filter of the file /application/controller/Pengeluaran.php. The manipulation of the argument dari/sampai leads to…

  • CVE-2023-6771MedDec 13, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Simple Student Attendance System 1.0. This issue affects the function save_attendance of the file actions.class.php. The manipulation of the argument sid leads to sql injection. The exploit has…

  • CVE-2023-6658MedDec 10, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability classified as critical was found in SourceCodester Simple Student Attendance System 1.0. This vulnerability affects unknown code of the file ajax-api.php?action=save_attendance. The manipulation of the argument class_id leads to sql injection. The exploit has…

  • CVE-2023-6657MedDec 10, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Simple Student Attendance System 1.0. This affects an unknown part of the file /modals/student_form.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the…

  • CVE-2023-6619MedDec 8, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /modals/class_form.php. The manipulation of the argument id leads to sql injection. The exploit has…

  • CVE-2023-6618MedDec 8, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument page leads to file inclusion. The exploit has…

Page 17 of 22