VYPR

Vendor CVEs

Oretnom23

All CVEs

1,064 total · sorted by risk
  • CVE-2023-6617MedDec 8, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been classified as critical. Affected is an unknown function of the file attendance.php. The manipulation of the argument class_id leads to sql injection. The exploit has been disclosed to…

  • CVE-2026-30520MedMar 31, 2026
    risk 0.35cvss 5.4epss 0.00

    A Blind SQL Injection vulnerability exists in SourceCodester Loan Management System v1.0. The vulnerability is located in the ajax.php file (specifically the save_loan action). The application fails to properly sanitize user input supplied to the "borrower_id" parameter in a…

  • CVE-2026-30527MedMar 27, 2026
    risk 0.35cvss 5.4epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Category management module within the admin panel. The application fails to properly sanitize user input supplied to the "Category Name" field when creating or…

  • CVE-2025-13468MedNov 20, 2025
    risk 0.35cvss 5.4epss 0.00

    A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_forum/delete_career/delete_comment/delete_gallery/delete_event of the file admin/admin_class.php of the component Delete Handler. Executing manipulation of the…

  • CVE-2024-40069MedApr 16, 2025
    risk 0.35cvss 5.4epss 0.00

    Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/Users.php?f=save, and the point of vulnerability is in the POST parameter 'firstname' and 'lastname'.

  • CVE-2025-2652MedMar 23, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to exposure of information through directory listing. The attack…

  • CVE-2025-2651MedMar 23, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /oews/admin/. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack…

  • CVE-2024-51032MedNov 8, 2024
    risk 0.35cvss 5.4epss 0.00

    A Cross-site Scripting (XSS) vulnerability in manage_recipient.php of Sourcecodester Toll Tax Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "owner" input field.

  • CVE-2024-51031MedNov 8, 2024
    risk 0.35cvss 5.4epss 0.00

    A Cross-site Scripting (XSS) vulnerability in manage_account.php in Sourcecodester Cab Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "First Name," "Middle Name," and "Last Name" fields.

  • CVE-2024-8711MedSep 12, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in SourceCodester Food Ordering Management System 1.0. Affected by this issue is some unknown functionality of the file /includes/. The manipulation leads to exposure of information through directory listing.…

  • CVE-2024-7753MedAug 14, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /user_images/. The manipulation leads to direct request. The attack can be initiated remotely. The exploit…

  • CVE-2024-37856MedJul 29, 2024
    risk 0.35cvss 5.4epss 0.00

    Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the first, last, middle name fields in the User Profile page.

  • CVE-2024-35468MedMay 30, 2024
    risk 0.35cvss 5.4epss 0.00

    A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.

  • CVE-2023-24204MedMay 14, 2024
    risk 0.35cvss 5.4epss 0.01

    SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitrary code via the name parameter in get-quote.php.

  • CVE-2023-24203MedMay 14, 2024
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitary code via the company or query parameter(s).

  • CVE-2023-23019MedMay 1, 2024
    risk 0.35cvss 5.4epss 0.00

    Cross site scripting (XSS) vulnerability in file main.php in sourcecodester oretnom23 Blog Site 1.0 via the name and email parameters to function user_add.\

  • CVE-2024-31649MedApr 15, 2024
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Name parameter.

  • CVE-2024-31544MedApr 9, 2024
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in Computer Laboratory Management System v1.0 allows attackers to execute arbitrary JavaScript code by including malicious payloads into “remarks”, “borrower_name”, “faculty_department” parameters in…

  • CVE-2024-3139MedApr 1, 2024
    risk 0.35cvss 5.4epss 0.00

    A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue is the function save_users of the file /classes/Users.php?f=save. The manipulation of the argument id leads to improper…

  • CVE-2023-51281MedMar 7, 2024
    risk 0.35cvss 5.4epss 0.00

    Cross Site Scripting vulnerability in Customer Support System v.1.0 allows a remote attacker to escalate privileges via a crafted script firstname, "lastname", "middlename", "contact" and address parameters.

  • CVE-2023-49987MedMar 7, 2024
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability in the component /management/term of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tname parameter.

  • CVE-2023-49977MedMar 6, 2024
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the address parameter at /customer_support/index.php?page=new_customer.

  • CVE-2023-49976MedMar 6, 2024
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability in Customer Support System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the subject parameter at /customer_support/index.php?page=new_ticket.

  • CVE-2023-43944MedSep 29, 2023
    risk 0.35cvss 5.4epss 0.00

    A Stored Cross Site Scripting (XSS) vulnerability was found in SourceCodester Task Management System 1.0. It allows attackers to execute arbitrary code via parameter field in index.php?page=project_list.

  • CVE-2023-44048MedSep 27, 2023
    risk 0.35cvss 5.4epss 0.00

    Sourcecodester Expense Tracker App v1 is vulnerable to Cross Site Scripting (XSS) via add category.

  • CVE-2023-43456MedSep 25, 2023
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting vulnerability in Service Provider Management System v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the firstname, middlename and lastname parameters in the /php-spms/admin/?page=user endpoint.

  • CVE-2023-2152MedApr 18, 2023
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument page leads to file inclusion. The…

  • CVE-2023-1956MedApr 8, 2023
    risk 0.35cvss 5.4epss 0.01

    A vulnerability classified as critical was found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=delete_img of the component Image Handler. The manipulation of the argument path…

  • CVE-2023-24651MedFeb 27, 2023
    risk 0.35cvss 5.4epss 0.01

    Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter on the registration page.

  • CVE-2022-45613MedJan 18, 2023
    risk 0.35cvss 5.4epss 0.00

    Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the publisher parameter.

  • CVE-2022-45033MedDec 15, 2022
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability in Expense Tracker 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Chat text field.

  • CVE-2022-42069MedOct 14, 2022
    risk 0.35cvss 5.4epss 0.00

    Online Birth Certificate Management System version 1.0 suffers from a persistent Cross Site Scripting (XSS) vulnerability.

  • CVE-2021-41434MedSep 28, 2022
    risk 0.35cvss 5.4epss 0.01

    A stored Cross-Site Scripting (XSS) vulnerability exists in version 1.0 of the Expense Management System application that allows for arbitrary execution of JavaScript commands through index.php.

  • CVE-2022-37796MedSep 12, 2022
    risk 0.35cvss 5.4epss 0.00

    In Simple Online Book Store System 1.0 in /admin_book.php the Title, Author, and Description parameters are vulnerable to Cross Site Scripting(XSS).

  • CVE-2022-30494MedMay 26, 2022
    risk 0.35cvss 5.4epss 0.01

    In oretnom23 Automotive Shop Management System v1.0, the first and last name user fields suffer from a stored XSS Injection Vulnerability allowing remote attackers to gain admin access and view internal IPs.

  • CVE-2022-30837MedMay 24, 2022
    risk 0.35cvss 5.4epss 0.01

    Toll-tax-management-system v1.0 is vulnerable to Cross Site Scripting (XSS) via /ttms/classes/Master.php?f=save_recipient, vehicle_name.

  • CVE-2022-24582MedFeb 24, 2022
    risk 0.35cvss 5.4epss 0.01

    Accounting Journal Management 1.0 is vulnerable to XSS-PHPSESSID-Hijacking. The parameter manage_user from User lists is vulnerable to XSS-Stored and PHPSESSID attacks. The malicious user can attack the system by using the already session which he has from inside and outside of…

  • CVE-2024-9321MedSep 29, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in SourceCodester Online Railway Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/inquiries/view_details.php. The manipulation of the argument id leads to improper access controls. The…

  • CVE-2024-7929MedAug 19, 2024
    risk 0.34cvss 5.3epss 0.00

    A vulnerability, which was classified as problematic, was found in SourceCodester Simple Forum Website 1.0. This affects an unknown part of the file /registration.php of the component Signup Page. The manipulation of the argument username leads to cross site scripting. It is…

  • CVE-2024-7799MedAug 15, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /simple-online-bidding-system/bidding/admin/users.php. The manipulation leads to improper authorization.…

  • CVE-2024-5045MedMay 17, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in SourceCodester Online Birth Certificate Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin. The manipulation leads to files or directories accessible. The attack can be initiated…

  • CVE-2024-33302MedMay 2, 2024
    risk 0.34cvss 5.3epss 0.00

    SourceCodester Product Show Room 1.0 and before is vulnerable to Cross Site Scripting (XSS) via "Middle Name" under Add Users.

  • CVE-2024-40070MedApr 16, 2025
    risk 0.33cvss 5.1epss 0.00

    Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/Users.php?f=save. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2023-0686MedFeb 6, 2023
    risk 0.33cvss 5.0epss 0.01

    A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been classified as critical. This affects the function update_cart of the file /oews/classes/Master.php?f=update_cart of the component HTTP POST Request Handler. The manipulation of the argument cart_id…

  • CVE-2023-0673MedFeb 4, 2023
    risk 0.33cvss 5.0epss 0.00

    A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerability is an unknown functionality of the file oews/?p=products/view_product.php. The manipulation of the argument id leads to sql injection. The attack can be…

  • CVE-2022-3714MedOct 27, 2022
    risk 0.33cvss 5.0epss 0.00

    A vulnerability classified as critical has been found in SourceCodester Online Medicine Ordering System 1.0. Affected is an unknown function of the file admin/?page=orders/view_order. The manipulation of the argument id leads to sql injection. It is possible to launch the attack…

  • CVE-2023-49544MedMar 1, 2024
    risk 0.32cvss 4.9epss 0.01

    A local file inclusion (LFI) in Customer Support System v1 allows attackers to include internal PHP files and gain unauthorized acces via manipulation of the page= parameter at /customer_support/index.php.

  • CVE-2026-3752MedMar 8, 2026
    risk 0.31cvss 4.7epss 0.00

    A flaw has been found in SourceCodester Employee Task Management System up to 1.0. The affected element is an unknown function of the file /daily-task-report.php of the component GET Parameter Handler. This manipulation of the argument Date causes sql injection. It is possible…

  • CVE-2026-3751MedMar 8, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was detected in SourceCodester Employee Task Management System 1.0. Impacted is an unknown function of the file /daily-attendance-report.php of the component GET Parameter Handler. The manipulation of the argument Date results in sql injection. The attack may be…

  • CVE-2025-6873MedJun 29, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability, which was classified as critical, has been found in SourceCodester Simple Company Website 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=save. The manipulation of the argument img leads to unrestricted upload. The attack may be…

Page 18 of 22