VYPR

Vendor CVEs

Oretnom23

All CVEs

1,064 total · sorted by risk
  • CVE-2025-6872MedJun 29, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability classified as critical was found in SourceCodester Simple Company Website 1.0. This vulnerability affects unknown code of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument img leads to unrestricted upload. The attack can be…

  • CVE-2025-6870MedJun 29, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /classes/Content.php?f=service. The manipulation of the argument img leads to unrestricted upload. The attack…

  • CVE-2025-6869MedJun 29, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/testimonials/manage.php. The manipulation of the argument ID leads to sql injection. The attack…

  • CVE-2025-6868MedJun 29, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/clients/manage.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack…

  • CVE-2025-6867MedJun 29, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in SourceCodester Simple Company Website 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/services/manage.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely.…

  • CVE-2025-4267MedMay 5, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability, which was classified as critical, was found in SourceCodester/oretnom23 Stock Management System 1.0. This affects an unknown part of the file /admin/?page=purchase_order/view_po of the component Purchase Order Details Page. The manipulation of the argument ID…

  • CVE-2024-40074MedApr 16, 2025
    risk 0.31cvss 4.8epss 0.00

    Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/SystemSettings.php?f=update_settings, and the point of vulnerability is in the POST parameter 'short_name'.

  • CVE-2025-2852MedMar 27, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability has been found in SourceCodester Food Ordering Management System up to 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/menus/view_menu.php. The manipulation of the argument ID leads to sql injection.…

  • CVE-2022-46091MedMar 7, 2024
    risk 0.31cvss 4.7epss 0.00

    Cross Site Scripting (XSS) vulnerability in the feedback form of Online Flight Booking Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the airline parameter.

  • CVE-2023-49986MedMar 7, 2024
    risk 0.31cvss 4.7epss 0.00

    A cross-site scripting (XSS) vulnerability in the component /admin/parent of School Fees Management System 1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.

  • CVE-2024-2152MedMar 4, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Online Mobile Management Store 1.0. Affected by this issue is some unknown functionality of the file /admin/product/manage_product.php. The manipulation of the argument id leads to sql injection.…

  • CVE-2024-0502MedJan 13, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester House Rental Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file manage_user.php of the component Edit User. The manipulation of the argument id/name/username leads to sql…

  • CVE-2023-5423MedOct 5, 2023
    risk 0.31cvss 4.7epss 0.00

    A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/ajax.php?action=confirm_order. The manipulation of the argument id leads to sql injection. The attack can be…

  • CVE-2023-36317MedAug 23, 2023
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) vulnerability in sourcecodester Student Study Center Desk Management System 1.0 allows attackers to run arbitrary code via crafted GET request to web application URL.

  • CVE-2023-2369MedApr 28, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Faculty Evaluation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file admin/manage_restriction.php. The manipulation of the argument id leads to sql injection. The attack may be initiated…

  • CVE-2023-1407MedMar 15, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as critical was found in SourceCodester Student Study Center Desk Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/user/manage_user.php. The manipulation of the argument id leads to sql injection. The…

  • CVE-2023-0257MedJan 12, 2023
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /fos/admin/index.php?page=menu of the component Menu Form. The manipulation of the argument Image…

  • CVE-2022-45008MedDec 7, 2022
    risk 0.31cvss 4.8epss 0.00

    Online Leave Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /leave_system/admin/?page=maintenance/department. This vulnerability allows attackers to execute arbitrary web scripts or HTML via crafted payload…

  • CVE-2022-4278MedDec 3, 2022
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Human Resource Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /hrm/employeeadd.php. The manipulation of the argument empid leads to sql injection. The attack may be…

  • CVE-2022-43046MedNov 7, 2022
    risk 0.31cvss 4.8epss 0.00

    Food Ordering Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /foms/place-order.php.

  • CVE-2022-3549MedOct 17, 2022
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /csms/admin/?page=user/manage_user of the component Avatar Handler. The manipulation leads to…

  • CVE-2022-35117MedAug 17, 2022
    risk 0.31cvss 4.8epss 0.01

    Clinic's Patient Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via update_medicine_details.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Packing text box…

  • CVE-2024-57523MedFeb 6, 2025
    risk 0.29cvss 4.5epss 0.00

    Cross Site Request Forgery (CSRF) in Users.php in SourceCodester Packers and Movers Management System 1.0 allows attackers to create unauthorized admin accounts via crafted requests sent to an authenticated admin user.

  • CVE-2026-3770MedMar 8, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part. This manipulation causes cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been published and may be used.

  • CVE-2026-3702MedMar 8, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was detected in SourceCodester Loan Management System 1.0. Affected by this issue is some unknown functionality of the file /index.php. Performing a manipulation of the argument page results in cross site scripting. The attack is possible to be carried out…

  • CVE-2026-2160MedFeb 8, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /tourism/classes/Master.php?f=save_package. The manipulation of the argument Title leads to cross site scripting. The…

  • CVE-2026-2159MedFeb 8, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected is an unknown function of the file /tourism/classes/Master.php?f=register of the component Registration. Executing a manipulation of the argument firstname/lastname/username can lead to cross…

  • CVE-2026-1745MedFeb 2, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in SourceCodester Medical Certificate Generator App 1.0. This affects an unknown part. This manipulation causes cross-site request forgery. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

  • CVE-2025-6476MedJun 22, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in SourceCodester Gym Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to…

  • CVE-2025-4282MedMay 5, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /classes/Users.php?f=save. The manipulation leads to cross-site request forgery. The attack can be initiated…

  • CVE-2025-3298MedApr 5, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product of the component Registration Handler. The manipulation of the…

  • CVE-2024-40443MedNov 13, 2024
    risk 0.28cvss 4.3epss 0.01

    SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php

  • CVE-2024-9300MedSep 28, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic was found in SourceCodester Online Railway Reservation System 1.0. This vulnerability affects unknown code of the file contact_us.php of the component Message Us Form. The manipulation of the argument fullname/email/message leads to…

  • CVE-2024-9298MedSep 28, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in SourceCodester Online Railway Reservation System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /?page=tickets of the component Ticket Handler. The manipulation of the argument id leads to…

  • CVE-2024-8604MedSep 9, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic has been found in SourceCodester Online Food Ordering System 2.0. This affects an unknown part of the file index.php of the component Create an Account Page. The manipulation of the argument First Name/Last Name leads to cross site…

  • CVE-2024-8558MedSep 7, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic was found in SourceCodester Food Ordering Management System 1.0. This vulnerability affects unknown code of the file /foms/routers/place-order.php of the component Price Handler. The manipulation of the argument total leads to improper…

  • CVE-2024-8555MedSep 7, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in SourceCodester Clinics Patient Management System 2.0. It has been classified as problematic. Affected is an unknown function of the file congratulations.php. The manipulation of the argument goto_page leads to open redirect. It is possible to launch…

  • CVE-2024-7662MedAug 12, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problematic. This vulnerability affects the function save_package of the file admin/packages/manag_package.php. The manipulation leads to cross-site request forgery. The…

  • CVE-2024-7661MedAug 12, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been classified as problematic. This affects the function save_users of the file admin/user/index.php. The manipulation leads to cross-site request forgery. It is possible to initiate…

  • CVE-2024-7645MedAug 12, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file users.php of the component User Page. The manipulation leads to cross-site request forgery. The attack can…

  • CVE-2024-7367MedAug 1, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, was found in SourceCodester Simple Realtime Quiz System 1.0. This affects an unknown part of the file /ajax.php?action=save_user. The manipulation leads to cross-site request forgery. It is possible to initiate the attack…

  • CVE-2024-7360MedAug 1, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic has been found in SourceCodester Tracking Monitoring Management System 1.0. This affects an unknown part of the file /ajax.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The…

  • CVE-2024-7226MedJul 30, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in SourceCodester Medicine Tracker System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /classes/Users.php?f=save_user of the component Password Change Handler. The manipulation leads to cross-site request…

  • CVE-2024-7169MedJul 28, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic has been found in SourceCodester School Fees Payment System 1.0. This affects an unknown part of the file /ajax.php. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has…

  • CVE-2024-6649MedJul 10, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is the function save_users of the file Users.php. The manipulation leads to cross-site request forgery. The attack can…

  • CVE-2024-6273MedJun 23, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as problematic. Affected by this vulnerability is the function save_patient of the file patient_side.php. The manipulation of the argument Full Name/Contact/Address leads to cross site…

  • CVE-2024-5897MedJun 12, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=log_visitor. The manipulation of the argument name leads…

  • CVE-2024-5428MedMay 28, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic was found in SourceCodester Simple Online Bidding System 1.0. Affected by this vulnerability is the function save_product of the file /admin/index.php?page=manage_product of the component HTTP POST Request Handler. The manipulation leads…

  • CVE-2024-5123MedMay 20, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic has been found in SourceCodester Event Registration System 1.0. This affects an unknown part of the file /registrar/. The manipulation of the argument searchbar leads to cross site scripting. It is possible to initiate the attack…

  • CVE-2024-4929MedMay 16, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic has been found in SourceCodester Simple Online Bidding System 1.0. This affects an unknown part of the file /simple-online-bidding-system/admin/ajax.php?action=save_user. The manipulation leads to cross-site request forgery. It is…

Page 19 of 22