VYPR

Vendor CVEs

Projectworlds

All CVEs

258 total · sorted by risk
  • CVE-2021-46024CriJan 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No login is required.

  • CVE-2021-46307CriJan 21, 2022
    risk 0.64cvss 9.8epss 0.02

    An SQL Injection vulnerability exists in Projectworlds Online Examination System 1.0 via the eid parameter in account.php.

  • CVE-2021-43631CriDec 22, 2021
    risk 0.64cvss 9.8epss 0.01

    Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment.php.

  • CVE-2021-43629CriDec 22, 2021
    risk 0.64cvss 9.8epss 0.01

    Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php.

  • CVE-2021-43628CriDec 22, 2021
    risk 0.64cvss 9.8epss 0.01

    Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php.

  • CVE-2021-43157CriDec 22, 2021
    risk 0.64cvss 9.8epss 0.01

    Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php.

  • CVE-2021-43155CriDec 22, 2021
    risk 0.64cvss 9.8epss 0.01

    Projectsworlds Online Book Store PHP v1.0 is vulnerable to SQL injection via the "bookisbn" parameter in cart.php.

  • CVE-2020-19114CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in Online Book Store v1.0 via the publisher parameter to edit_book.php, which could let a remote malicious user execute arbitrary code.

  • CVE-2020-19113CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.03

    Arbitrary File Upload vulnerability in Online Book Store v1.0 in admin_add.php, which may lead to remote code execution.

  • CVE-2020-19112CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_delete.php, which could let a remote malicious user execute arbitrary code.

  • CVE-2020-19111CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.02

    Incorrect Access Control vulnerability in Online Book Store v1.0 via admin_verify.php, which could let a remote mailicious user bypass authentication and obtain sensitive information.

  • CVE-2020-19110CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to book.php parameter, which could let a remote malicious user execute arbitrary code.

  • CVE-2020-19109CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_edit.php, which could let a remote malicious user execute arbitrary code.

  • CVE-2020-19108CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in Online Book Store v1.0 via the pubid parameter to bookPerPub.php, which could let a remote malicious user execute arbitrary code.

  • CVE-2020-19107CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.02

    SQL Injection vulnerability in Online Book Store v1.0 via the isbn parameter to edit_book.php, which could let a remote malicious user execute arbitrary code.

  • CVE-2020-23833CriSep 15, 2020
    risk 0.64cvss 9.8epss 0.04

    Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers to execute arbitrary code on the hosting webserver via a malicious index.php POST request.

  • CVE-2020-24199CriSep 9, 2020
    risk 0.64cvss 9.8epss 0.04

    Arbitrary File Upload in the Vehicle Image Upload component in Project Worlds Car Rental Management System v1.0 allows attackers to conduct remote code execution.

  • CVE-2020-24115CriAug 31, 2020
    risk 0.64cvss 9.8epss 0.02

    In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to admin panel access.

  • CVE-2020-24203CriAug 27, 2020
    risk 0.64cvss 9.8epss 0.04

    Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management System v1.0 allows remote unauthenticated attackers to gain remote code execution.

  • CVE-2020-24202CriAug 27, 2020
    risk 0.64cvss 9.8epss 0.03

    File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regular users, which allows remote attackers to conduct code execution.

  • CVE-2020-11545CriApr 6, 2020
    risk 0.64cvss 9.8epss 0.02

    Project Worlds Official Car Rental System 1 is vulnerable to multiple SQL injection issues, as demonstrated by the email and parameters (account.php), uname and pass parameters (login.php), and id parameter (book_car.php) This allows an attacker to dump the MySQL database and to…

  • CVE-2025-70146CriFeb 18, 2026
    risk 0.59cvss 9.1epss 0.01

    Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting records) via direct HTTP requests to affected…

  • CVE-2024-51060CriOct 31, 2024
    risk 0.59cvss 9.1epss 0.00

    Projectworlds Online Admission System v1 is vulnerable to SQL Injection in index.php via the 'a_id' parameter.

  • CVE-2023-5185CriSep 28, 2023
    risk 0.59cvss 9.1epss 0.01

    Gym Management System Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'file' parameter of profile/i.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

  • CVE-2025-60311HigOct 8, 2025
    risk 0.57cvss 8.8epss 0.00

    ProjectWorlds Gym Management System1.0 is vulnerable to SQL Injection via the "id" parameter in the profile/edit.php page

  • CVE-2024-36597HigJun 14, 2024
    risk 0.57cvss 8.8epss 0.02

    Aegon Life v1.0 was discovered to contain a SQL injection vulnerability via the client_id parameter at clientStatus.php.

  • CVE-2023-44482HigDec 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setsickleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-44481HigDec 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setearnleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45121HigDec 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'desc' parameter of the /update.php?q=addquiz resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45120HigDec 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'qid' parameter of the /update.php?q=quiz&step=2 resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45119HigDec 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'n' parameter of the /update.php?q=quiz resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45118HigDec 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'fdid' parameter of the /update.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45117HigDec 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'eid' parameter of the /update.php?q=rmquiz resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45116HigDec 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'demail' parameter of the /update.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-45115HigDec 21, 2023
    risk 0.57cvss 8.8epss 0.01

    Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'ch' parameter of the /update.php?q=addqns resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-44480HigOct 27, 2023
    risk 0.57cvss 8.8epss 0.01

    Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setcasualleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.

  • CVE-2023-43014HigSep 28, 2023
    risk 0.57cvss 8.8epss 0.01

    Asset Management System v1.0 is vulnerable to an Authenticated SQL Injection vulnerability on the 'first_name' and 'last_name' parameters of user.php page, allowing an authenticated attacker to dump all the contents of the database contents.

  • CVE-2023-43740HigSep 28, 2023
    risk 0.57cvss 8.8epss 0.01

    Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_edit.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

  • CVE-2021-43630HigDec 22, 2021
    risk 0.57cvss 8.8epss 0.02

    Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in add_patient.php. As a result, an authenticated malicious user can compromise the databases system and in some cases leverage this vulnerability to get remote code execution on…

  • CVE-2020-27397HigDec 23, 2020
    risk 0.57cvss 8.8epss 0.03

    Marital - Online Matrimonial Project In PHP version 1.0 suffers from an authenticated file upload vulnerability allowing remote attackers to gain remote code execution (RCE) on the Hosting web server via uploading a maliciously crafted PHP file.

  • CVE-2020-25760HigSep 30, 2020
    risk 0.57cvss 8.8epss 0.02

    Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input validation on the 'rid' parameter. An attacker can append SQL queries to the input to extract sensitive information from the database.

  • CVE-2024-22983HigFeb 28, 2024
    risk 0.53cvss 8.1epss 0.01

    SQL injection vulnerability in Projectworlds Visitor Management System in PHP v.1.0 allows a remote attacker to escalate privileges via the name parameter in the myform.php endpoint.

  • CVE-2025-8471HigAug 2, 2025
    risk 0.50cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in projectworlds Online Admission System 1.0. This issue affects some unknown processing of the file /adminlogin.php. The manipulation of the argument a_id leads to sql injection. The attack may be initiated…

  • CVE-2025-70147HigFeb 18, 2026
    risk 0.49cvss 7.5epss 0.01

    Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET requests to these endpoints without a…

  • CVE-2024-51326HigNov 4, 2024
    risk 0.49cvss 7.5epss 0.01

    SQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote attacker to execute arbitrary code via the 't2' parameter in deletesubcategory.php.

  • CVE-2021-44866HigFeb 3, 2022
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An attacker can append SQL queries to the input to extract sensitive information from the database.

  • CVE-2025-4457HigMay 9, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in Project Worlds Car Rental Project 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/approve.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely.…

  • CVE-2025-4456HigMay 9, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in Project Worlds Car Rental Project 1.0. Affected is an unknown function of the file /signup.php. The manipulation of the argument fname leads to sql injection. It is possible to launch the attack remotely. The exploit has…

  • CVE-2025-2661HigMar 23, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in Project Worlds Online Time Table Generator 1.0 and classified as critical. This issue affects some unknown processing of the file /staff/index.php. The manipulation of the argument e leads to sql injection. The attack may be initiated remotely. The…

  • CVE-2026-9364HigMay 24, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in projectworlds Online Art Gallery Shop 1.0. Impacted is an unknown function of the file /admin/adminHome.php. Executing a manipulation of the argument social_linked can lead to sql injection. The attack can be executed remotely. The exploit has been…

Page 2 of 6