PatchSiren

code-projects CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW code-projects CVE published 2026-10-05

CVE-2026-105188

A vulnerability was found in code-projects Human Resource Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /views/admin/liveEventHistory.php of the component Live Event History. The manipulation of the argument eventSubject results in cross site scripting. The attack may be launched remotely. This vulnerability could potentially allow attackers to inject malici [truncated]

LOW code-projects CVE published 2026-10-05

CVE-2026-105173

A cross-site scripting vulnerability exists in the Human Resource Management 1.0 system, specifically in the EventStore.php file. This could allow an attacker to inject malicious scripts into the application. The vulnerability is triggered by manipulating the eventSubject argument, which could lead to potential system integrity and user data impacts. Defenders should prioritize verifying system exposure, [truncated]

MEDIUM code-projects CVE published 2026-09-20

CVE-2026-93980

A weakness has been identified in code-projects Internship Management System 1.0. This vulnerability affects unknown code of the file /admin/login.php of the component Admin Login Form. Executing a manipulation of the argument Password can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

MEDIUM code-projects CVE published 2026-09-20

CVE-2026-93979

A security flaw has been discovered in code-projects Internship Management System 1.0, affecting the /employer/login.php file. Performing a manipulation of the argument Password results in SQL injection, allowing for potential remote exploitation. The exploit has been released to the public and may be used for attacks. This vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. Defenders should a [truncated]

MEDIUM code-projects CVE published 2026-09-20

CVE-2026-93978

A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of the argument Password leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. This vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. Defenders should assess [truncated]

LOW code-projects CVE published 2026-09-20

CVE-2026-93977

A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this vulnerability is an unknown functionality of the file lecturer/add-single-mark.php. This manipulation of the argument mark causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

LOW code-projects CVE published 2026-09-20

CVE-2026-93976

A vulnerability was found in code-projects Assessment Management 1.0. Affected is an unknown function of the file admin/add-user.php. The manipulation of the argument level results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used. This vulnerability affects Assessment Management 1.0 systems, specifically within the admin/add-user.php file, al [truncated]

LOW code-projects CVE published 2026-09-20

CVE-2026-93975

A vulnerability was found in code-projects Assessment Management 1.0, specifically in the admin/edit-user.php file of the User Editing component. The manipulation of certain arguments leads to cross-site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability impacts the confidentiality, integrity, and availability of the system. De [truncated]

LOW code-projects CVE published 2026-09-15

CVE-2026-91854

A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the file main/reg.php. Such manipulation of the argument desc leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used. This cross-site scripting vulnerability could allow remote attackers to inject malicious scripts, potentially le [truncated]

MEDIUM code-projects CVE published 2026-09-08

CVE-2026-86519

A vulnerability was found in code-projects Student Crud Operation 1.0, impacting the Backup File Handler component's /card_activation.sql file, leading to potential information disclosure. The attack can be launched remotely, and the exploit has been made public. Defenders should assess potential risks and verify exposure, especially for publicly accessible Backup File Handlers. This vulnerability allows [truncated]

LOW code-projects CVE published 2026-09-08

CVE-2026-86518

A vulnerability was found in code-projects Student Crud Operation 1.0, affecting an unknown function of the file /edit.php. The manipulation of the argument ID leads to SQL injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This vulnerability has significant implications for defenders, as it can be exploited to gain unauthorized access to sensiti [truncated]

MEDIUM code-projects CVE published 2026-09-07

CVE-2026-86302

A vulnerability was found in code-projects Hospital Information System 1.0, specifically in the SQL Database Backup File Handler. This issue allows for information disclosure via remote exploitation. The exploit has been made public. Defenders should assess exposure, verify vendor remediation status, and monitor for potential information disclosure attempts. The vulnerability is located in the SQL Databas [truncated]

LOW code-projects CVE published 2026-09-07

CVE-2026-86301

A vulnerability was found in the Hospital Information System 1.0, specifically in the /HIS/src/patients/editPatient.php file of the Patient Management component. The vulnerability is due to cross-site scripting (XSS) caused by improper handling of the ID argument. This issue can be exploited remotely, potentially impacting patient data confidentiality and healthcare services. Defenders should verify the p [truncated]

LOW code-projects CVE published 2026-09-04

CVE-2026-85643

A SQL injection vulnerability exists in the admin/adduser.php file of the Code-projects Online Shopping System 1.0. The vulnerability is due to improper sanitization of user input in the mobile argument of the mysqli_query function. This could allow an attacker to execute malicious SQL code remotely. The vulnerability has been publicly disclosed and may be used by attackers. Defenders should assess exposu [truncated]

MEDIUM code-projects CVE published 2026-08-31

CVE-2026-82624

A flaw in Simple Inventory System 1.0's Database Backup File Handler in the inventorymanagement.sql file may cause information disclosure. The attack may be initiated remotely. The vulnerability is related to the handling of database backup files, which could potentially lead to unauthorized access to sensitive information. The affected product, Simple Inventory System 1.0, is a software application desig [truncated]

LOW code-projects CVE published 2026-08-31

CVE-2026-82622

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-31T07:17:46.533Z and has not been modified since then. The cross-site scripting vulnerability in Employee Leave Managing System 1.0, specifically in the /EmpManageSys/editaction.php file, is triggered by manipulating the 'Name' argument, allowing for remote attacks. Organizations using Employee Leav [truncated]

MEDIUM code-projects CVE published 2026-08-25

CVE-2026-79845

The CVE-2026-79845 vulnerability in code-projects Simple Inventory System 1.0 is a SQL injection issue in the /InventoryManagement/edit.php file. This vulnerability is caused by improper handling of the ID argument, allowing remote attackers to inject malicious SQL code. Organizations should be aware of this vulnerability and take steps to patch it. The CVE record was published on 2026-08-25T22:17:06.860Z [truncated]

MEDIUM code-projects CVE published 2026-08-20

CVE-2026-76990

CVE-2026-76990 is a SQL injection vulnerability in the /delete.php file of Simple Inventory System 1.0. The vulnerability allows remote exploitation through manipulation of the ID argument. Organizations using this system should prioritize patching and implement input validation. The CVE record, published on 2026-08-20T14:18:00.313Z, indicates a CVSS score of 5.5 and a severity of MEDIUM. Reviewing offici [truncated]

MEDIUM code-projects CVE published 2026-08-20

CVE-2026-76764

A SQL injection vulnerability exists in the Employee Management System 1.0, specifically in the /process/aprocess.php file of the Admin Login Endpoint. The manipulation of the 'mailuid' argument can lead to SQL injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. This vulnerability could allow attackers to execute arbitrary SQL queries, potentially lead [truncated]

MEDIUM code-projects CVE published 2026-08-20

CVE-2026-76762

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T00:16:52.817Z and has not been modified since then. The vulnerability, CVE-2026-76762, is a SQL injection issue in Code Projects Assessment Management 1.0, specifically in the /welcome.php file. The manipulation of the 'userid' argument results in SQL injection, which can be exploited remotely. O [truncated]

MEDIUM code-projects CVE published 2026-08-19

CVE-2026-75986

CVE-2026-75986 is a SQL injection vulnerability in the /ForPass.php file of the Password Recovery component in code-projects Online Job Portal System 1.0. The vulnerability is triggered by manipulation of the txtUserName argument and may allow remote exploitation. This issue impacts organizations using the affected system, as it could lead to unauthorized access or data manipulation. Security teams should [truncated]

LOW code-projects CVE published 2026-08-10

CVE-2026-19378

The CVE-2026-19378 vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the file /user/CommentSave.php, leading to cross-site scripting. The attack can be launched remotely. Users should verify the existence of this vulnerability and apply patches or mitigations as necessary. This includes administrators, security teams, and operators who may b [truncated]

MEDIUM code-projects CVE published 2026-08-09

CVE-2026-19345

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-09T10:17:10.387Z and has not been modified since then. CVE-2026-19345 is a missing authorization vulnerability in Task Management System 1.0, affecting the UpdateTaskStatus.php file. The vulnerability allows remote attackers to manipulate task status without proper authorization, potentially impacti [truncated]

MEDIUM code-projects CVE published 2026-08-09

CVE-2026-19344

CVE-2026-19344 is a SQL injection vulnerability in the /user/comment_count_user.php file of the Task Management System 1.0 by code-projects. The vulnerability allows for remote attacks and has been publicly disclosed. The CVSS score is 5.5, indicating a medium severity level. This vulnerability can be exploited remotely, and attackers can manipulate the task_id argument to inject malicious SQL code. The a [truncated]

MEDIUM code-projects CVE published 2026-08-09

CVE-2026-19343

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-09T08:16:47.710Z and has not been modified since then. The vulnerability affects Code-projects Task Management System 1.0, specifically an unknown functionality of the file /admin/AdminLogin.php, allowing for SQL injection through manipulation of the email and password arguments. This could enable a [truncated]

MEDIUM code-projects CVE published 2026-08-09

CVE-2026-19342

The Task Management System 1.0, developed by code-projects, contains a vulnerability in its login functionality located in the /index.php file. This vulnerability, tracked as CVE-2026-19342, is caused by improper authentication when the Password argument is manipulated, allowing for remote exploitation. The affected component is the login function, which is a critical part of the system. The vulnerability [truncated]

MEDIUM code-projects CVE published 2026-07-30

CVE-2025-65342

Organizations should be aware of a Cross Site Scripting (XSS) vulnerability in code-projects Blood System 1.0, specifically in the /don.php file via the city field. This vulnerability has a CVSS score of 6.1 and is classified as MEDIUM severity. The CVE record was published on 2026-07-30T21:16:51.777Z and has not been modified since then. Affected organizations should review and apply patches or workaroun [truncated]

LOW code-projects CVE published 2026-07-19

CVE-2026-16220

A vulnerability has been found in code-projects Online Examination System 1.0. This vulnerability affects unknown code of the file /account.php?q=quiz. Such manipulation of the argument eid/n/t leads to cross site scripting. The attack can be launched remotely. Users of code-projects Online Examination System 1.0 should be aware of this cross site scripting vulnerability and take steps to mitigate it. The [truncated]

MEDIUM code-projects CVE published 2026-07-17

CVE-2026-16014

A SQL injection vulnerability was found in the Login Form of Hospital Bed Management System 1.0. The vulnerability is caused by improper handling of the Username argument, allowing an attacker to inject malicious SQL code. This can lead to unauthorized access to sensitive data. Remote exploitation of this vulnerability is possible. The CVSS score for this vulnerability is 5.5, indicating a medium severity [truncated]

LOW code-projects CVE published 2026-07-14

CVE-2026-15678

A security vulnerability has been detected in code-projects Online Job Portal 1.0. This impacts an unknown function of the file /Admin/DetailJob.php. The manipulation leads to cross site scripting. The attack is possible to be carried out remotely. The vulnerability is a cross site scripting (XSS) issue in the /Admin/DetailJob.php file of code-projects Online Job Portal 1.0. Users of code-projects Online [truncated]