VYPR

Vendor CVEs

Projectworlds

All CVEs

256 total · sorted by risk
  • CVE-2025-13253MedNov 17, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in projectworlds Advanced Library Management System 1.0. This affects an unknown part of the file /add_librarian.php. This manipulation of the argument Username causes sql injection. The attack is possible to be carried out remotely. The exploit…

  • CVE-2025-12862MedNov 7, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php. Such manipulation of the argument image leads to unrestricted upload. The attack may be performed from…

  • CVE-2025-11426MedOct 8, 2025
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_book.php. The manipulation of the argument image results in unrestricted upload. It is possible to launch the…

  • CVE-2025-8247MedJul 28, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability classified as critical has been found in Projectworlds Online Admission System 1.0. This affects an unknown part of the file /admin.php. The manipulation of the argument markof leads to sql injection. It is possible to initiate the attack remotely. The exploit…

  • CVE-2025-6136MedJun 16, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in Projectworlds Life Insurance Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /insertPayment.php. The manipulation of the argument recipt_no leads to sql injection. The attack may be…

  • CVE-2025-6135MedJun 16, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in Projectworlds Life Insurance Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /insertNominee.php. The manipulation of the argument client_id/nominee_id leads to sql injection. The attack can…

  • CVE-2025-6134MedJun 16, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in Projectworlds Life Insurance Management System 1.0. It has been classified as critical. This affects an unknown part of the file /insertClient.php. The manipulation of the argument client_id leads to sql injection. It is possible to initiate the…

  • CVE-2025-6133MedJun 16, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in Projectworlds Life Insurance Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /insertagent.php. The manipulation of the argument agent_id leads to sql injection. The attack may be…

  • CVE-2025-3042MedApr 1, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. This vulnerability affects unknown code of the file /student/updateprofile.php. The manipulation of the argument pic leads to unrestricted upload. The attack can be initiated…

  • CVE-2025-3041MedApr 1, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file /admin/updatestudent.php. The manipulation of the argument pic leads to unrestricted upload. It is possible to initiate the attack…

  • CVE-2025-3040MedMar 31, 2025
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add_student.php. The manipulation of the argument pic leads to unrestricted upload. The attack may…

  • CVE-2025-2662MedMar 23, 2025
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been classified as critical. Affected is an unknown function of the file student/studentdashboard.php. The manipulation of the argument course leads to sql injection. It is possible to launch the…

  • CVE-2024-12950MedDec 26, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in code-projects/projectworlds Travel Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /subcat.php. The manipulation of the argument catid leads to sql injection. The attack may be initiated…

  • CVE-2024-11059MedNov 11, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in Project Worlds Free Download Online Shopping System up to 192.168.1.88. It has been rated as critical. This issue affects some unknown processing of the file /online-shopping-webvsite-in-php-master/success.php. The manipulation of the argument id…

  • CVE-2024-10735MedNov 3, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Project Worlds Life Insurance Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /editNominee.php. The manipulation of the argument nominee_id leads to sql injection. The attack can be…

  • CVE-2024-10734MedNov 3, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Project Worlds Life Insurance Management System 1.0. It has been classified as critical. This affects an unknown part of the file /editPayment.php. The manipulation of the argument recipt_no leads to sql injection. It is possible to initiate the…

  • CVE-2024-10447MedOct 28, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1.0. Affected by this vulnerability is an unknown functionality of the file /timetable/staff/staffdashboard.php?info=updateprofile. The manipulation of the argument n leads to sql…

  • CVE-2024-10446MedOct 28, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in Project Worlds Online Time Table Generator 1.0. Affected is an unknown function of the file /timetable/admin/admindashboard.php?info=add_course. The manipulation of the argument c leads to sql injection. It is possible to…

  • CVE-2024-10425MedOct 27, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Project Worlds Student Project Allocation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /student/project_selection/move_up_project.php of the component Project Selection Page. The manipulation…

  • CVE-2024-10424MedOct 27, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability has been found in Project Worlds Student Project Allocation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /student/project_selection/remove_project.php of the component Project Selection Page. The…

  • CVE-2024-10423MedOct 27, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, was found in Project Worlds Student Project Allocation System 1.0. Affected is an unknown function of the file /student/project_selection/project_selection.php of the component Project Selection Page. The manipulation of the…

  • CVE-2024-0783MedJan 22, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Project Worlds Online Admission System 1.0 and classified as critical. This issue affects some unknown processing of the file documents.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been…

  • CVE-2024-0730MedJan 19, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, was found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file course_ajax.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely.…

  • CVE-2024-0498MedJan 13, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in Project Worlds Lawyer Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file searchLawyer.php. The manipulation of the argument experience leads to sql injection. The attack can…

  • CVE-2023-3694MedJul 17, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester/projectworlds House Rental and Property Listing 1.0. This issue affects some unknown processing of the file /index.php. The manipulation of the argument keywords/location leads to sql injection.…

  • CVE-2024-51328MedNov 4, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in addcategory.php in projectworld's Travel Management System v1.0 allows remote attacker to inject arbitrary code via the t2 parameter.

  • CVE-2023-45203MedNov 1, 2023
    risk 0.40cvss 6.1epss 0.00

    Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.

  • CVE-2023-45202MedNov 1, 2023
    risk 0.40cvss 6.1epss 0.00

    Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the feed.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.

  • CVE-2023-45201MedNov 1, 2023
    risk 0.40cvss 6.1epss 0.00

    Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the admin.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.

  • CVE-2023-44484MedOct 31, 2023
    risk 0.40cvss 6.1epss 0.00

    Online Blood Donation Management System v1.0 is vulnerable to a Stored Cross-Site Scripting vulnerability. The 'firstName' parameter of the users/register.php resource is copied into the users/member.php document as plain text between tags. Any input is echoed unmodified in the…

  • CVE-2022-42066MedOct 14, 2022
    risk 0.40cvss 6.1epss 0.01

    Online Examination System version 1.0 suffers from a cross site scripting vulnerability via index.php.

  • CVE-2020-26006MedMay 24, 2021
    risk 0.40cvss 6.1epss 0.01

    Project Worlds Online Examination System 1.0 is affected by Cross Site Scripting (XSS) via account.php.

  • CVE-2020-29205MedMay 17, 2021
    risk 0.40cvss 6.1epss 0.02

    XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via the name field

  • CVE-2020-23832MedOct 6, 2020
    risk 0.40cvss 6.1epss 0.02

    A Persistent Cross-Site Scripting (XSS) vulnerability in message_admin.php in Projectworlds Car Rental Management System v1.0 allows unauthenticated remote attackers to harvest an admin login session cookie and steal an admin session upon an admin login.

  • CVE-2020-25761MedSep 30, 2020
    risk 0.40cvss 6.1epss 0.02

    Projectworlds Visitor Management System in PHP 1.0 allows XSS. The file myform.php does not perform input validation on the request parameters. An attacker can inject javascript payloads in the parameters to perform various attacks such as stealing of cookies,sensitive…

  • CVE-2024-45986MedSep 26, 2024
    risk 0.35cvss 5.4epss 0.00

    A stored Cross-Site Scripting (XSS) vulnerability was identified in Projectworld Online Voting System 1.0 that occurs when an account is registered with a malicious javascript payload. The payload is stored and subsequently executed in the voter.php and profile.php pages…

  • CVE-2023-44173MedSep 28, 2023
    risk 0.35cvss 5.4epss 0.00

    Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Reflected Cross-Site Scripting vulnerability.

  • CVE-2021-45852MedMar 16, 2022
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in Projectworlds Hospital Management System v1.0. Unauthorized malicious attackers can add patients without restriction via add_patient.php.

  • CVE-2025-11103MedSep 28, 2025
    risk 0.31cvss 4.7epss 0.00

    A security vulnerability has been detected in Projectworlds Online Tours and Travels 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/change-image.php. The manipulation of the argument packageimage leads to unrestricted upload. The attack may be…

  • CVE-2024-0726MedJan 19, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in Project Worlds Student Project Allocation System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file admin_login.php of the component Admin Login Module. The manipulation of the argument msg with the input…

  • CVE-2024-0650MedJan 18, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in Project Worlds Visitor Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file dataset.php of the component URL Handler. The manipulation of the argument name with the input…

  • CVE-2024-0266MedJan 7, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic has been found in Project Worlds Online Lawyer Management System 1.0. Affected is an unknown function of the component User Registration. The manipulation of the argument First Name leads to cross site scripting. It is possible to launch…

  • CVE-2021-43158MedDec 22, 2021
    risk 0.28cvss 4.3epss 0.00

    In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to remove any product in the customer's cart.

  • CVE-2026-4626LowMar 24, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in projectworlds Lawyer Management System 1.0. This impacts an unknown function of the file /lawyer_booking.php. The manipulation of the argument Description leads to cross site scripting. The attack may be initiated remotely. The exploit has been…

  • CVE-2026-4596LowMar 23, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was identified in projectworlds Lawyer Management System 1.0. This issue affects some unknown processing of the file /lawyers.php. The manipulation of the argument first_Name leads to cross site scripting. The attack may be initiated remotely. The exploit is…

  • CVE-2026-1700LowJan 30, 2026
    risk 0.23cvss 3.5epss 0.00

    A weakness has been identified in projectworlds House Rental and Property Listing 1.0. This vulnerability affects unknown code of the file /app/sms.php. This manipulation of the argument Message causes cross site scripting. It is possible to initiate the attack remotely. The…

  • CVE-2025-12227LowOct 27, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was determined in projectworlds Gate Pass Management System 1.0. The affected element is an unknown function of the file /add-pass.php. Executing a manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly…

  • CVE-2024-10433LowOct 28, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in Project Worlds Simple Web-Based Chat Application 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument Name/Comment leads to cross site scripting. The attack…

  • CVE-2026-0642LowJan 7, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was detected in projectworlds House Rental and Property Listing 1.0. This issue affects some unknown processing of the file /app/complaint.php. The manipulation of the argument Name results in cross site scripting. The attack may be launched remotely. The exploit…

  • CVE-2025-12231LowOct 27, 2025
    risk 0.16cvss 2.4epss 0.00

    A security vulnerability has been detected in projectworlds Expense Management System 1.0. Affected is an unknown function of the file /public/admin/expense_categories/create of the component Expense Categories Page. Such manipulation leads to cross site scripting. It is…

Page 5 of 6