VYPR

Vendor CVEs

Projectworlds

All CVEs

256 total · sorted by risk
  • CVE-2025-4837HigMay 17, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in projectworlds Student Project Allocation System 1.0. This affects an unknown part of the file /make_group_sql.php. The manipulation of the argument mem1/mem2/mem3 leads to sql injection. It is possible to initiate the…

  • CVE-2025-4836HigMay 17, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Projectworlds Life Insurance Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /deleteAgent.php. The manipulation of the argument agent_id leads to sql injection. The attack may be…

  • CVE-2025-4739HigMay 16, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in projectworlds Hospital Database Management System 1.0. It has been classified as critical. This affects an unknown part of the file /medicines_info.php. The manipulation of the argument Med_ID leads to sql injection. It is possible to initiate the…

  • CVE-2025-4706HigMay 15, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in projectworlds Online Examination System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /Procedure3b_yearwiseVisit.php. The manipulation of the argument Visit_year leads to sql injection. The attack can be…

  • CVE-2025-4482HigMay 9, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in Project Worlds Student Project Allocation System 1.0. Affected by this vulnerability is an unknown functionality of the file /change_pass/forgot_password_sql.php. The manipulation of the argument Pat_BloodGroup1 leads to sql…

  • CVE-2025-4058HigApr 29, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in Projectworlds Online Examination System 1.0. This affects an unknown part of the file /Bloodgroop_process.php. The manipulation of the argument Pat_BloodGroup1 leads to sql injection. It is possible to initiate the attack…

  • CVE-2025-4034HigApr 28, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in projectworlds Online Examination System 1.0. Affected by this vulnerability is an unknown functionality of the file /inser_doc_process.php. The manipulation of the argument Doc_ID leads to sql injection. The attack can be…

  • CVE-2025-3186HigApr 4, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /patient/invoice.php. The manipulation of the argument appid leads to sql injection.…

  • CVE-2025-3185HigApr 3, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been classified as critical. Affected is an unknown function of the file /patient/patientupdateprofile.php. The manipulation of the argument patientFirstName leads to sql injection.…

  • CVE-2025-3184HigApr 3, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0 and classified as critical. This issue affects some unknown processing of the file /patient/profile.php?patientId=1. The manipulation of the argument patientFirstName leads to sql injection.…

  • CVE-2025-3183HigApr 3, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in projectworlds Online Doctor Appointment Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /patient/patientupdateprofile.php. The manipulation of the argument patientFirstName leads to sql…

  • CVE-2025-3182HigApr 3, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in projectworlds Online Doctor Appointment Booking System 1.0. This affects an unknown part of the file /patient/getschedule.php. The manipulation of the argument q leads to sql injection. It is possible to initiate…

  • CVE-2025-3181HigApr 3, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in projectworlds Online Doctor Appointment Booking System 1.0. Affected by this issue is some unknown functionality of the file /patient/appointment.php?scheduleDate=1&appid=1. The manipulation of the argument…

  • CVE-2025-3180HigApr 3, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in projectworlds Online Doctor Appointment Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /doctor/deleteschedule.php. The manipulation of the argument ID leads to sql injection. The…

  • CVE-2025-3179HigApr 3, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in projectworlds Online Doctor Appointment Booking System 1.0. Affected is an unknown function of the file /doctor/deletepatient.php. The manipulation of the argument ic leads to sql injection. It is possible to launch the…

  • CVE-2025-3178HigApr 3, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /doctor/deleteappointment.php. The manipulation of the argument ID leads to sql injection. The attack…

  • CVE-2025-3176HigApr 3, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Project Worlds Online Lawyer Management System 1.0. It has been classified as critical. This affects an unknown part of the file /single_lawyer.php. The manipulation of the argument u_id leads to sql injection. It is possible to initiate the attack…

  • CVE-2025-3175HigApr 3, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /save_user_edit_profile.php. The manipulation of the argument first_Name leads to sql injection. The…

  • CVE-2025-3174HigApr 3, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /searchLawyer.php. The manipulation of the argument experience leads to sql injection. The…

  • CVE-2025-3173HigApr 3, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in Project Worlds Online Lawyer Management System 1.0. Affected is an unknown function of the file /save_booking.php. The manipulation of the argument lawyer_id/description leads to sql injection. It is possible to…

  • CVE-2025-3172HigApr 3, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability, which was classified as critical, has been found in Project Worlds Online Lawyer Management System 1.0. This issue affects some unknown processing of the file /lawyer_booking.php. The manipulation of the argument unblock_id leads to sql injection. The attack may…

  • CVE-2025-3171HigApr 3, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in Project Worlds Online Lawyer Management System 1.0. This vulnerability affects unknown code of the file /approve_lawyer.php. The manipulation of the argument unblock_id leads to sql injection. The attack can be initiated…

  • CVE-2025-3170HigApr 3, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in Project Worlds Online Lawyer Management System 1.0. This affects an unknown part of the file /admin_user.php. The manipulation of the argument block_id/unblock_id leads to sql injection. It is possible to initiate the…

  • CVE-2025-2660HigMar 23, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in Project Worlds Online Time Table Generator 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument e leads to sql injection. The attack can be initiated remotely. The…

  • CVE-2025-2659HigMar 23, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability, which was classified as critical, was found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file /student/index.php. The manipulation of the argument e leads to sql injection. It is possible to initiate the attack remotely.…

  • CVE-2025-2657HigMar 23, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability classified as critical was found in projectworlds Apartment Visitors Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /front.php. The manipulation of the argument rid leads to sql injection. The attack can be launched…

  • CVE-2025-2067HigMar 7, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in projectworlds Life Insurance Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /search.php. The manipulation of the argument key leads to sql injection. The attack may be initiated remotely. The…

  • CVE-2025-2066HigMar 7, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in projectworlds Life Insurance Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /updateAgent.php. The manipulation of the argument agent_id leads to sql injection. The attack can be initiated…

  • CVE-2025-2065HigMar 7, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in projectworlds Life Insurance Management System 1.0. This affects an unknown part of the file /editAgent.php. The manipulation of the argument agent_id leads to sql injection. It is possible to initiate the attack…

  • CVE-2025-2064HigMar 7, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in projectworlds Life Insurance Management System 1.0. Affected by this issue is some unknown functionality of the file /deletePayment.php. The manipulation of the argument recipt_no leads to sql injection. The…

  • CVE-2025-2063HigMar 7, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in projectworlds Life Insurance Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /deleteNominee.php. The manipulation of the argument nominee_id leads to sql injection. The attack can…

  • CVE-2025-2062HigMar 7, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in projectworlds Life Insurance Management System 1.0. Affected is an unknown function of the file /clientStatus.php. The manipulation of the argument client_id leads to sql injection. It is possible to launch the attack…

  • CVE-2025-1965HigMar 5, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in projectworlds Online Hotel Booking 1.0. Affected is an unknown function of the file /admin/login.php. The manipulation of the argument emailusername leads to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2025-1964HigMar 5, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been rated as critical. This issue affects some unknown processing of the file /booknow.php?roomname=Duplex. The manipulation of the argument checkin leads to sql injection. The attack may be initiated…

  • CVE-2025-1963HigMar 5, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /reservation.php. The manipulation of the argument checkin leads to sql injection. The attack can be initiated remotely. The…

  • CVE-2025-1962HigMar 5, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in projectworlds Online Hotel Booking 1.0. It has been classified as critical. This affects an unknown part of the file /admin/addroom.php. The manipulation of the argument roomname leads to sql injection. It is possible to initiate the attack remotely.…

  • CVE-2024-10432HigOct 28, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in Project Worlds Simple Web-Based Chat Application 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /index.php. The manipulation of the argument username leads to sql injection. The attack can…

  • CVE-2020-11544HigApr 6, 2020
    risk 0.47cvss 7.2epss 0.01

    An issue was discovered in Project Worlds Official Car Rental System 1. It allows the admin user to run commands on the server with their account because the upload section on the file-manager page contains an arbitrary file upload vulnerability via add_cars.php. There are no…

  • CVE-2024-45987MedSep 26, 2024
    risk 0.42cvss 6.5epss 0.00

    Projectworld Online Voting System Version 1.0 is vulnerable to Cross Site Request Forgery (CSRF) via voter.php. This vulnerability allows an attacker to craft a malicious link that, when clicked by an authenticated user, automatically submits a vote for a specified party without…

  • CVE-2023-44174MedSep 28, 2023
    risk 0.42cvss 6.4epss 0.00

    Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Stored Cross-Site Scripting vulnerability.

  • CVE-2021-43156MedDec 22, 2021
    risk 0.42cvss 6.5epss 0.01

    In ProjectWorlds Online Book Store PHP 1.0 a CSRF vulnerability in admin_delete.php allows a remote attacker to delete any book.

  • CVE-2020-25411MedMay 24, 2021
    risk 0.42cvss 6.5epss 0.01

    Projectworlds Online Examination System 1.0 is vulnerable to CSRF, which allows a remote attacker to delete the existing user.

  • CVE-2020-25408MedMay 24, 2021
    risk 0.42cvss 6.5epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability exists in ProjectWorlds College Management System Php 1.0 that allows a remote attacker to modify, delete, or make a new entry of the student, faculty, teacher, subject, scores, location, and article data.

  • CVE-2026-10875MedJun 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in projectworlds Online Art Gallery Shop Project 1.0. The impacted element is an unknown function of the file /admin/adminHome.ph. The manipulation of the argument social_twitter results in sql injection. The attack may be launched remotely.…

  • CVE-2026-10874MedJun 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in projectworlds Online Art Gallery Shop Project 1.0. The affected element is an unknown function of the file /admin/adminHome.php. The manipulation of the argument social_insta leads to sql injection. The attack may be initiated remotely. The…

  • CVE-2025-13573MedNov 24, 2025
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in projectworlds can pass malicious payloads up to 1.0. This vulnerability affects unknown code of the file /add_book.php. The manipulation of the argument image results in unrestricted upload. The attack can be executed remotely. The exploit…

  • CVE-2025-13278MedNov 17, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /borrowed_book_search.php. Such manipulation of the argument datefrom/dateto leads to sql injection. The attack can be launched remotely. The…

  • CVE-2025-13256MedNov 17, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /borrow.php. Executing a manipulation of the argument roll_number can lead to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2025-13255MedNov 17, 2025
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. This issue affects some unknown processing of the file /book_search.php. Performing a manipulation of the argument book_pub/book_title results in sql injection. It is possible to…

  • CVE-2025-13254MedNov 17, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This vulnerability affects unknown code of the file /add_member.php. Such manipulation of the argument roll_number leads to sql injection. The attack may be performed from remote. The exploit…

Page 4 of 6