VYPR
Vendor

Vishalmathur

Products
4
CVEs
14
Across products
14
Status
Private

Products

4

Recent CVEs

14
  • CVE-2025-52410CriNov 20, 2025
    risk 0.64cvss 9.8epss 0.00

    Institute-of-Current-Students v1.0 contains a time-based blind SQL injection vulnerability in the mydetailsstudent.php endpoint. The `myds` GET parameter is not adequately sanitized before being used in SQL queries.

  • CVE-2025-55444CriAug 20, 2025
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts MCA Project 1.0. A remote attacker can inject arbitrary SQL queries, leading to database enumeration and potential remote code execution.

  • CVE-2025-46179CriJun 20, 2025
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was discovered in the askquery.php file of CloudClassroom-PHP Project v1.0. The squeryx parameter accepts unsanitized input, which is passed directly into backend SQL queries.

  • CVE-2025-26199CriJun 18, 2025
    risk 0.64cvss 9.8epss 0.00

    CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transmits passwords over unencrypted HTTP during the login process, exposing sensitive credentials to potential interception by network-based attackers. A remote…

  • CVE-2025-26198CriJun 18, 2025
    risk 0.64cvss 9.8epss 0.01

    CloudClassroom-PHP-Project v1.0 contains a critical SQL Injection vulnerability in the loginlinkadmin.php component. The application fails to sanitize user-supplied input in the admin login form before directly including it in SQL queries. This allows unauthenticated attackers…

  • CVE-2025-45542HigJun 2, 2025
    risk 0.51cvss 7.3epss 0.01

    SQL injection vulnerability in the registrationform endpoint of CloudClassroom-PHP-Project v1.0. The pass parameter is vulnerable due to improper input validation, allowing attackers to inject SQL queries.

  • CVE-2026-2058HigFeb 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file /postquerypublic.php of the component Post Query Details Page. This manipulation of the argument gnamex causes sql…

  • CVE-2024-57459HigJun 2, 2025
    risk 0.47cvss 7.3epss 0.00

    A time-based SQL injection vulnerability exists in mydetailsstudent.php in the CloudClassroom PHP Project 1.0. The myds parameter does not properly validate user input, allowing an attacker to inject arbitrary SQL commands.

  • CVE-2025-50867MedJul 31, 2025
    risk 0.42cvss 6.5epss 0.00

    A SQL Injection vulnerability exists in the takeassessment2.php endpoint of the CloudClassroom-PHP-Project 1.0, where the Q5 POST parameter is directly embedded in SQL statements without sanitization.

  • CVE-2025-44608MedJul 25, 2025
    risk 0.42cvss 6.5epss 0.00

    CloudClassroom-PHP Project v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter.

  • CVE-2025-50866MedJul 31, 2025
    risk 0.40cvss 6.1epss 0.00

    CloudClassroom-PHP-Project 1.0 contains a reflected Cross-site Scripting (XSS) vulnerability in the email parameter of the postquerypublic endpoint. Improper sanitization allows an attacker to inject arbitrary JavaScript code that executes in the context of the user s browser,…

  • CVE-2025-51411MedJul 25, 2025
    risk 0.40cvss 6.1epss 0.00

    A reflected cross-site scripting (XSS) vulnerability exists in Institute-of-Current-Students v1.0 via the email parameter in the /postquerypublic endpoint. The application fails to properly sanitize user input before reflecting it in the HTML response. This allows…

  • CVE-2025-46178MedJun 9, 2025
    risk 0.40cvss 6.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability exists in askquery.php via the eid parameter in the CloudClassroom PHP Project. This allows remote attackers to inject arbitrary JavaScript in the context of a victim s browser session by sending a crafted URL, leading to session…

  • CVE-2024-57423MedFeb 26, 2025
    risk 0.40cvss 6.1epss 0.00

    A Cross Site Scripting vulnerability in CloudClassroom-PHP Project v1.0 allows a remote attacker to execute arbitrary code via the exid parameter of the assessment function.