Skip to content
Threat Feed

Vendor

Code-Projects

52 briefs RSS
high advisory

SQL Injection in code-projects Matrimonial System

Matrimonial System 1.0 contains a remote SQL injection vulnerability in the search.php script, allowing unauthenticated attackers to manipulate search arguments to execute arbitrary database commands.

Matrimonial System sqli web-vulnerability
1r 1t 1c
high advisory

SQL Injection in code-projects Task Management System In PHP

The code-projects Task Management System In PHP version 1.0 is susceptible to an unauthenticated remote SQL injection vulnerability in the login component via the email parameter.

Task Management System In PHP
1r 1t 1c
high advisory

SQL Injection in code-projects Content Management System

A SQL injection vulnerability in the user_name parameter of the login.php file in code-projects Content Management System 1.0 allows for remote, unauthenticated command execution.

Content Management System
1r 1t 1c
high advisory

SQL Injection in Vehicle Management System

Vehicle Management System version 1.0 contains an SQL injection vulnerability in the busid parameter of /busprofile.php, allowing unauthenticated remote attackers to execute arbitrary SQL queries.

Vehicle Management System web-vulnerability sqli vulnerability
1r 1t 1c
high advisory

SQL Injection Vulnerability in Hospital Information System 1.0

An unauthenticated SQL injection vulnerability in the Hospital Information System 1.0 allows remote attackers to execute unauthorized database queries via the Search parameter in addReq.php.

Hospital Information System web-application-vulnerability sql-injection cve-2026-85397 vulnerability web
2r 1t 1c
high advisory

SQL Injection in Doctor Appointment System 1.0

An SQL injection vulnerability in the email parameter of the patient_login.php file allows unauthenticated remote attackers to execute arbitrary SQL commands in Doctor Appointment System 1.0.

Doctor Appointment System web-vulnerability sqli vulnerability-management injection cve-2026-85403
2r 1t 1c
high advisory

SQL Injection Vulnerability in Online Shopping System

The Online Shopping System 1.0 contains an unauthenticated SQL injection vulnerability in the search functionality of /action.php, allowing remote attackers to execute arbitrary database queries.

Online Shopping System sqli vulnerability web-application
1r 1t 1c
high advisory

SQL Injection in Barangay Resident Profiling Management System

An unauthenticated SQL injection vulnerability in the Barangay Resident Profiling Management System version 1.0 allows remote attackers to execute arbitrary database queries via the 'Search' argument in residents.php.

Barangay Resident Profiling Management System web-application-vulnerability sql-injection cve-2026-78143
1r 1t 1c
high advisory

SQL Injection Vulnerability in Simple Inventory System

An unauthenticated SQL injection vulnerability in the delete.php file of Simple Inventory System 1.0 allows remote attackers to execute arbitrary database queries via the ID parameter.

Simple Inventory System
1r 1t 1c
high advisory

SQL Injection in Employee Management System

Employee Management System 1.0 is vulnerable to unauthenticated SQL injection via the 'mailuid' parameter in the '/process/aprocess.php' administrative login endpoint, allowing for remote exploitation.

Employee Management System
1r 1t 1c
high threat

SQL Injection in code-projects Assessment Management 1.0

An unauthenticated SQL injection vulnerability in the /welcome.php file of Assessment Management 1.0 allows remote attackers to execute arbitrary SQL commands via the userid parameter.

exploited Assessment Management
1r 1t 1c
high threat

SQL Injection Vulnerability in Hospital Information System 1.0

Hospital Information System 1.0 is vulnerable to unauthenticated remote SQL injection via the 'email' parameter in the User::login function, allowing for unauthorized database access.

exploited Hospital Information System
1r 1t 1c
high threat

SQL Injection Vulnerability in Online Job Portal System

Online Job Portal System 1.0 is vulnerable to unauthenticated remote SQL injection via the txtUserName parameter in the /ForPass.php file, allowing potential unauthorized database access.

exploited Online Job Portal System
1r 1t 1c
high advisory

SQL Injection Vulnerability in code-projects Task Management System

An unauthenticated remote SQL injection vulnerability in code-projects Task Management System 1.0 allows attackers to execute arbitrary SQL commands via the email parameter in the login form.

Task Management System web-injection sql-injection cve-2026-75778
1r 1t 1c
high advisory

Improper Authentication in code-projects Task Management System

A vulnerability in code-projects Task Management System 1.0 allows remote attackers to bypass authentication via manipulation of the password argument in the login component.

Task Management System web-application authentication-bypass cve-2026-19342 web-vulnerability sql-injection cve-2026-19343
1r 2t 3c
high advisory

Critical SQL Injection Vulnerability in Hospital Bed Management System (CVE-2026-16014)

A critical SQL injection vulnerability, CVE-2026-16014, has been identified in the Login Form component of code-projects Hospital Bed Management System version 1.0, allowing remote attackers to manipulate the 'Username' argument for unauthorized data access and manipulation, with a public exploit available.

Hospital Bed Management System 1.0 sql-injection web-application cve data-exfiltration
1r 3t 1c 6i
high advisory

Remote SQL Injection Vulnerability in code-projects Online Job Portal (CVE-2026-15676)

A high-severity SQL injection vulnerability, CVE-2026-15676, exists in code-projects Online Job Portal up to version 1.0, allowing remote unauthenticated attackers to manipulate the database via the /Admin/DeleteUser.php file with a publicly available exploit.

Online Job Portal <= 1.0 sql-injection web-vulnerability cve
1r 2t 1c
high advisory

Remote SQL Injection in code-projects Online Job Portal (CVE-2026-15675)

A SQL injection vulnerability (CVE-2026-15675) has been identified in code-projects Online Job Portal version 1.0, located in the `/Admin/EditUser.php` file and triggered by manipulating the `UserId` argument, allowing for remote SQL injection attacks with publicly available exploit code.

Online Job Portal 1.0 sql-injection web-application cve vulnerability rce unrestricted-upload
2r 5t 1c
high threat

CVE-2026-15137: Remote SQL Injection in code-projects Interview Management System

A critical SQL injection vulnerability (CVE-2026-15137) has been identified in code-projects Interview Management System version 1.0, allowing remote unauthenticated attackers to manipulate the 'ID' argument in the '/inc/classes/View.php' file, leading to arbitrary SQL query execution and potential data compromise; a public exploit is available.

exploited Interview Management System 1.0 sql-injection webserver vulnerability cve code-projects interview-management-system
1r 2t 1c 6i
high threat

CVE-2026-15135 - SQL Injection in code-projects Online Food Order System

A high-severity SQL injection vulnerability, CVE-2026-15135, exists in code-projects Online Food Order System 1.0 affecting the `/edit_food_items.php` file's 'update' argument, allowing remote attackers to perform unauthorized data disclosure or manipulation, with a public exploit available.

exploited Online Food Order System 1.0 web-exploitation sql-injection cve data-exfiltration data-manipulation
1r 3t 1c 7i
high advisory

CVE-2026-14769 — SQL Injection in code-projects Real State Services 1.0

A critical security vulnerability, CVE-2026-14769, allows for remote SQL Injection in code-projects Real State Services 1.0 via the 'Bankname' argument in the '/pay.php' file, with a publicly disclosed exploit enabling information disclosure and potential data manipulation.

Real State Services 1.0 sql-injection web-vulnerability cve data-exfiltration
1r 3t 1c 6i
high advisory

CVE-2026-14768: Remote SQL Injection in code-projects Real State Services 1.0

A remote SQL injection vulnerability (CVE-2026-14768) has been identified in code-projects Real State Services 1.0, allowing attackers to exploit the 'loc' argument in '/builderHome.php' for arbitrary SQL command execution, with a public exploit available.

Real State Services 1.0 web-vulnerability sql-injection php cve
1r 1t 1c
high threat

CVE-2026-14764: SQL Injection in code-projects Hotel and Tourism Reservation

An unauthenticated attacker can remotely exploit CVE-2026-14764, an SQL injection vulnerability in code-projects Hotel and Tourism Reservation 1.0's `/admin/add_event.php` component via the `fdetails` argument, to manipulate database queries and compromise sensitive data, with public exploit disclosure increasing the risk of active exploitation.

exploited Hotel and Tourism Reservation 1.0 web-vulnerability sql-injection cve data-compromise webserver
1r 3t 1c
high threat

CVE-2026-14763: SQL Injection in code-projects Hotel and Tourism Reservation

A SQL injection vulnerability, tracked as CVE-2026-14763, has been discovered in code-projects Hotel and Tourism Reservation version 1.0. The flaw affects an unknown function within the '/admin/tour_reserves.php' file, specifically in the 'Tour Reservations Page' component, due to improper handling of the 'tour' argument, allowing for remote SQL injection attacks, and a public exploit is available, increasing the risk of compromise.

exploited Hotel and Tourism Reservation 1.0 sql-injection web-application cve data-exfiltration
1r 2t 1c 6i
high advisory

CVE-2026-14762: Remote SQL Injection in code-projects Hotel and Tourism Reservation

A critical SQL injection vulnerability (CVE-2026-14762) exists in code-projects Hotel and Tourism Reservation version 1.0, located in the `/admin/rooms.php` file's Room Management Page, allowing remote attackers to manipulate the `delete` argument for data compromise, with a public exploit now available.

Hotel and Tourism Reservation 1.0 sql-injection web-application cve php
1r 1t 1c
high threat

CVE-2026-14756: SQL Injection in code-projects Hotel and Tourism Reservation

A remote SQL injection vulnerability (CVE-2026-14756) exists in code-projects Hotel and Tourism Reservation version 1.0, allowing unauthenticated attackers to exploit improper input sanitization in the `delete_image` parameter of `/admin/add_tour.php` to bypass authentication, extract sensitive data, or manipulate database records, with a public exploit available.

exploited Hotel and Tourism Reservation 1.0 sql-injection web-application cve code-projects
1r 3t 1c 6i
high advisory

CVE-2026-14755: Remote SQL Injection in code-projects Hotel and Tourism Reservation

A critical remote unauthenticated SQL injection vulnerability (CVE-2026-14755) in code-projects Hotel and Tourism Reservation version 1.0, specifically within the '/admin/reservations.php' file's 'delete' argument, allows attackers to manipulate backend database queries, leading to data exposure and manipulation with a publicly disclosed exploit.

Hotel and Tourism Reservation 1.0 sql-injection web-vulnerability cve remote-code-execution data-exfiltration
1r 2t 1c 2i
high advisory

CVE-2026-14754: SQL Injection in code-projects Hotel and Tourism Reservation

A critical SQL injection vulnerability (CVE-2026-14754) in code-projects Hotel and Tourism Reservation 1.0's `/admin/add_room.php` file allows a remote, unauthenticated attacker to manipulate arguments such as `delete_image`, `edit`, `description`, `number`, `price`, `rooms`, or `type` to execute arbitrary SQL commands, leading to sensitive data exposure and potential database compromise.

Hotel and Tourism Reservation 1.0 sql-injection web-application cve code-projects remote-code-execution
1r 1t 1c
high advisory

CVE-2026-14747: SQL Injection in code-projects Real State Services 1.0

A high-severity SQL Injection vulnerability, CVE-2026-14747, exists in the /addprojectsale.php file of code-projects Real State Services 1.0, allowing remote unauthenticated attackers to manipulate the 'amen' argument for arbitrary SQL query execution, leading to data compromise or unauthorized access.

Real State Services 1.0 sql-injection web-exploitation cve php real-state
1r 1t 1c
high threat

CVE-2026-14746: SQL Injection in code-projects Real State Services

A high-severity SQL injection vulnerability (CVE-2026-14746) exists in code-projects Real State Services 1.0, specifically in the `/addprojectrent.php` file, where the `amen` argument can be manipulated to execute arbitrary SQL commands, enabling remote attackers to achieve unauthorized data access or modification, with public exploit disclosure increasing the risk of active exploitation.

exploited Real State Services 1.0 sql-injection web-vulnerability cve webserver public-exploit
1r 1t 1c
high advisory

CVE-2026-14745: SQL Injection in code-projects Real State Services

A critical SQL injection vulnerability (CVE-2026-14745) affecting code-projects Real State Services version 1.0 allows remote, unauthenticated attackers to execute arbitrary SQL commands by manipulating the 'ID' argument in the '/single-list_rent.php' file, potentially leading to data exposure, unauthorized modification, or denial of service, with a public exploit available.

Real State Services 1.0 web-vulnerability sql-injection cve real-estate vulnerability
1r 3t 1c
high advisory

CVE-2026-14744: Remote SQL Injection in code-projects Real State Services 1.0

A critical SQL injection vulnerability (CVE-2026-14744) has been found in code-projects Real State Services version 1.0. The flaw resides in an unknown function within the /normalHomeRent.php file, where manipulating the 'loc' argument allows for remote SQL injection, and a public exploit has been released, posing an immediate threat to affected systems.

Real State Services 1.0 web-exploitation sql-injection cve-2026-14744 initial-access data-exfiltration
1r 4t 1c 6i
high advisory

CVE-2026-14743: Remote SQL Injection in code-projects Real State Services 1.0

A high-severity remote SQL injection vulnerability (CVE-2026-14743) in code-projects Real State Services 1.0 allows an unauthenticated attacker to manipulate the 'loc' argument in the `/normalHomeSale.php` file, leading to arbitrary SQL command execution and potential compromise of confidentiality, integrity, and availability of data, with an exploit publicly available.

Real State Services 1.0 sql-injection webserver vulnerability cve
1r 2t 1c
high threat

CVE-2026-14735: SQL Injection Vulnerability in code-projects Smart Parking System

A high-severity SQL injection vulnerability, CVE-2026-14735, exists in code-projects Smart Parking System 1.0, allowing remote attackers to manipulate the `street`, `city`, or `status` arguments in `/parkings/parkings.php` to execute arbitrary SQL queries, potentially leading to arbitrary file read and data exfiltration, with public exploit details available.

exploited Smart Parking System 1.0 sql-injection vulnerability web-application php cve
1r 2t 1c 6i
high advisory

CVE-2026-14705: SQL Injection in code-projects Online Examination 1.0

A critical remote SQL injection vulnerability (CVE-2026-14705) exists in code-projects Online Examination 1.0, specifically within the `head.php` file, where manipulation of the `uname` or `password` arguments can lead to arbitrary SQL command execution, which has been publicly disclosed and can be exploited by an unauthenticated attacker.

Online Examination 1.0 sql-injection web-application cve initial-access
1r 1t 1c
high advisory

CVE-2026-14700: Code-Projects Internship Management System SQL Injection Vulnerability

A critical unauthenticated SQL injection vulnerability (CVE-2026-14700) in the 'employer/login.php' endpoint of code-projects Internship Management System 1.0 allows remote attackers to manipulate 'email' or 'password' arguments, potentially leading to unauthorized access and data compromise, with public exploit disclosure increasing risk.

Internship Management System 1.0 sql-injection web-application initial-access php unauthenticated
1r 1t 1c
high advisory

CVE-2026-14660: SQL Injection in code-projects Online Job Portal 1.0

A critical SQL injection vulnerability (CVE-2026-14660) exists in code-projects Online Job Portal version 1.0, specifically within the 'login.php' file, allowing remote attackers to bypass authentication or exfiltrate data by manipulating 'txtUser' and 'txtPass' arguments, with a public exploit increasing immediate risk.

Online Job Portal 1.0 sql-injection web-application cve initial-access
1r 1t 1c 5i
high advisory

CVE-2026-14649: Remote SQL Injection in code-projects Online Voting System

A remote SQL injection vulnerability (CVE-2026-14649) exists in code-projects Online Voting System version 1.0, located in the 'test_input' function within the '/saveVote.php' file, allowing an unauthenticated attacker to execute arbitrary SQL queries by manipulating 'voterName', 'voterEmail', 'voterID', or 'selectedCandidate' arguments.

Online Voting System 1.0 sql-injection web-application cve initial-access
1r 1t 1c
high threat

CVE-2026-14648: Remote SQL Injection in code-projects Online Voting System

A high-severity SQL injection vulnerability, identified as CVE-2026-14648, exists in the code-projects Online Voting System up to versions 0.x/1.0, allowing remote unauthenticated attackers to bypass authentication and execute arbitrary SQL commands by manipulating `adminUserName` or `adminPassword` parameters in the `/authentication.php` login component, with public exploit details increasing the risk of active exploitation.

exploited Online Voting System +1 sql-injection webserver vulnerability cve
1r 2t 1c
high advisory

CVE-2026-10290: Hotel and Tourism Reservation System SQL Injection Vulnerability

A SQL injection vulnerability exists in code-projects Hotel and Tourism Reservation System version 1.0 due to improper sanitization of the 'tour' GET parameter in the tour.php file, potentially allowing remote attackers to execute arbitrary SQL queries.

Hotel and Tourism Reservation System 1.0 cve sql-injection web-application
2r 1t 1c
high advisory

CVE-2026-10288 - code-projects Hotel and Tourism Reservation System Authentication Bypass

CVE-2026-10288 is a high severity vulnerability in code-projects Hotel and Tourism Reservation System 1.0, allowing remote attackers to bypass authentication via manipulation of the Password argument in the /admin/login.php file.

PoC Hotel and Tourism Reservation System 1.0 cve-2026-10288 authentication bypass web application
2r 2t 1c updated
high threat

code-projects Online Music Site 1.0 SQL Injection Vulnerability (CVE-2026-10178)

CVE-2026-10178 is a remote SQL injection vulnerability in code-projects Online Music Site 1.0, affecting the /Administrator/PHP/AdminEditAlbum.php file due to manipulation of the ID argument.

exploited Online Music Site 1.0 sql-injection web-application cve
2r 1t 1c
high advisory

CVE-2026-10110: SQL Injection Vulnerability in Student Details Management System

CVE-2026-10110 is a SQL injection vulnerability in code-projects Student Details Management System 1.0, allowing a remote attacker to execute arbitrary SQL commands by manipulating the 'roll' argument in the /index.php file, potentially leading to data breaches and unauthorized access.

Student Details Management System 1.0 sql-injection web-application
2r 1t 1c
high threat

code-projects Project Management System SQL Injection Vulnerability (CVE-2026-9584)

A SQL injection vulnerability (CVE-2026-9584) exists in code-projects Project Management System 1.0 within the chk.php file of the Login component, allowing a remote attacker to execute arbitrary SQL commands.

Project Management System 1.0 sql-injection cve-2026-9584 web-application injection
2r 1t 1c
high threat

code-projects Feedback System 1.0 SQL Injection Vulnerability (CVE-2026-8098)

A SQL injection vulnerability exists in code-projects Feedback System 1.0 via manipulation of the email parameter in /admin/checklogin.php, potentially allowing remote attackers to execute arbitrary SQL commands.

Feedback System 1.0 cve sql-injection web-application
2r 1t 1c
high advisory

code-projects Online Hospital Management System SQL Injection Vulnerability

CVE-2026-7632 is a SQL injection vulnerability in code-projects Online Hospital Management System 1.0, allowing a remote attacker to execute arbitrary SQL commands by manipulating the 'delid' argument in the '/viewappointment.php' file.

Online Hospital Management System 1.0 sql-injection web-application vulnerability
2r 1t 1c
critical advisory

code-projects Plugin 4.1.2cu.5137 Buffer Overflow Vulnerability

A buffer overflow vulnerability (CVE-2026-7503) exists in code-projects Plugin 4.1.2cu.5137, allowing a remote attacker to execute arbitrary code by manipulating the 'wepkey2' argument in the 'setWiFiMultipleConfig' function of the '/lib/cste_modules/wireless.so' library, posing a critical risk due to publicly available exploits.

Plugin 4.1.2cu.5137 buffer-overflow remote-code-execution cve-2026-7503
2r 2t 1c
high advisory

Online Lot Reservation System SQL Injection Vulnerability

CVE-2026-7131 is a SQL injection vulnerability in code-projects Online Lot Reservation System up to version 1.0, affecting the /loginuser.php component via manipulation of the email/password arguments, which could allow remote attackers to execute arbitrary SQL queries.

Online Lot Reservation System sql-injection web-application cve
2r 1t 1c
high advisory

SQL Injection Vulnerability in code-projects Inventory Management System 1.0

A SQL injection vulnerability exists in code-projects Inventory Management System 1.0 within the Login component, specifically affecting the Username argument, where a remote attacker can manipulate the Username parameter, leading to unauthorized data access or modification.

Inventory Management System 1.0 sql-injection web-application vulnerability
2r 1t 1c
high advisory

code-projects Employee Management System SQL Injection Vulnerability (CVE-2026-7063)

CVE-2026-7063 is a SQL Injection vulnerability in code-projects Employee Management System 1.0 via the 'pwd' parameter in /370project/process/eprocess.php, enabling remote attackers to execute arbitrary SQL commands.

Employee Management System 1.0 sqli cve-2026-7063 web-application
2r 1t 1c
high advisory

code-projects Vehicle Showroom Management System 1.0 SQL Injection Vulnerability

A remote SQL injection vulnerability exists in code-projects Vehicle Showroom Management System 1.0 via manipulation of the BRANCH_ID argument in the /util/BookVehicleFunction.php file, potentially allowing unauthorized database access.

Vehicle Showroom Management System cve-2026-6149 sql-injection web-application
2r 1t 1c
high advisory

Simple IT Discussion Forum 1.0 SQL Injection Vulnerability (CVE-2026-5672)

A remote SQL injection vulnerability exists in code-projects Simple IT Discussion Forum 1.0 via manipulation of the cat_id parameter in the /edit-category.php file.

Simple IT Discussion Forum sql-injection web-application vulnerability
2r 1t 1c