PatchSiren

code-projects CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM code-projects CVE published 2026-08-20

CVE-2026-76764

A SQL injection vulnerability exists in the Employee Management System 1.0, specifically in the /process/aprocess.php file of the Admin Login Endpoint. The manipulation of the 'mailuid' argument can lead to SQL injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. This vulnerability could allow attackers to execute arbitrary SQL queries, potentially lead [truncated]

LOW code-projects CVE published 2026-08-10

CVE-2026-19378

The CVE-2026-19378 vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the file /user/CommentSave.php, leading to cross-site scripting. The attack can be launched remotely. Users should verify the existence of this vulnerability and apply patches or mitigations as necessary. This includes administrators, security teams, and operators who may b [truncated]

MEDIUM code-projects CVE published 2026-08-09

CVE-2026-19345

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-09T10:17:10.387Z and has not been modified since then. CVE-2026-19345 is a missing authorization vulnerability in Task Management System 1.0, affecting the UpdateTaskStatus.php file. The vulnerability allows remote attackers to manipulate task status without proper authorization, potentially impacti [truncated]

MEDIUM code-projects CVE published 2026-08-09

CVE-2026-19344

CVE-2026-19344 is a SQL injection vulnerability in the /user/comment_count_user.php file of the Task Management System 1.0 by code-projects. The vulnerability allows for remote attacks and has been publicly disclosed. The CVSS score is 5.5, indicating a medium severity level. This vulnerability can be exploited remotely, and attackers can manipulate the task_id argument to inject malicious SQL code. The a [truncated]

MEDIUM code-projects CVE published 2026-08-09

CVE-2026-19343

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-09T08:16:47.710Z and has not been modified since then. The vulnerability affects Code-projects Task Management System 1.0, specifically an unknown functionality of the file /admin/AdminLogin.php, allowing for SQL injection through manipulation of the email and password arguments. This could enable a [truncated]

MEDIUM code-projects CVE published 2026-08-09

CVE-2026-19342

The Task Management System 1.0, developed by code-projects, contains a vulnerability in its login functionality located in the /index.php file. This vulnerability, tracked as CVE-2026-19342, is caused by improper authentication when the Password argument is manipulated, allowing for remote exploitation. The affected component is the login function, which is a critical part of the system. The vulnerability [truncated]

MEDIUM code-projects CVE published 2026-07-30

CVE-2025-65342

Organizations should be aware of a Cross Site Scripting (XSS) vulnerability in code-projects Blood System 1.0, specifically in the /don.php file via the city field. This vulnerability has a CVSS score of 6.1 and is classified as MEDIUM severity. The CVE record was published on 2026-07-30T21:16:51.777Z and has not been modified since then. Affected organizations should review and apply patches or workaroun [truncated]

LOW code-projects CVE published 2026-07-19

CVE-2026-16220

A vulnerability has been found in code-projects Online Examination System 1.0. This vulnerability affects unknown code of the file /account.php?q=quiz. Such manipulation of the argument eid/n/t leads to cross site scripting. The attack can be launched remotely. Users of code-projects Online Examination System 1.0 should be aware of this cross site scripting vulnerability and take steps to mitigate it. The [truncated]

MEDIUM code-projects CVE published 2026-07-17

CVE-2026-16014

A SQL injection vulnerability was found in the Login Form of Hospital Bed Management System 1.0. The vulnerability is caused by improper handling of the Username argument, allowing an attacker to inject malicious SQL code. This can lead to unauthorized access to sensitive data. Remote exploitation of this vulnerability is possible. The CVSS score for this vulnerability is 5.5, indicating a medium severity [truncated]

LOW code-projects CVE published 2026-07-14

CVE-2026-15678

A security vulnerability has been detected in code-projects Online Job Portal 1.0. This impacts an unknown function of the file /Admin/DetailJob.php. The manipulation leads to cross site scripting. The attack is possible to be carried out remotely. The vulnerability is a cross site scripting (XSS) issue in the /Admin/DetailJob.php file of code-projects Online Job Portal 1.0. Users of code-projects Online [truncated]

MEDIUM code-projects CVE published 2026-07-14

CVE-2026-15677

A weakness has been identified in code-projects Online Job Portal 1.0, specifically in the /JobSeekerInsert.php file. This affects an unknown function, allowing for unrestricted file upload through manipulation of the txtFile argument. The attack can be executed remotely, and the exploit has been made available to the public. Users of code-projects Online Job Portal 1.0 should be aware of this vulnerabili [truncated]

MEDIUM code-projects CVE published 2026-07-14

CVE-2026-15676

A security flaw has been discovered in Code-projects Online Job Portal up to 1.0. The impacted element is an unknown function of the file /Admin/DeleteUser.php. Performing a manipulation results in SQL injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. This vulnerability allows remote attackers to inject malicious SQL code, po [truncated]

MEDIUM code-projects CVE published 2026-07-14

CVE-2026-15675

A vulnerability was identified in code-projects Online Job Portal 1.0, specifically in the /Admin/EditUser.php file. The vulnerability allows for SQL injection attacks through manipulation of the UserId argument. The attack can be launched remotely, and the exploit is publicly available. This vulnerability has a CVSS score of 5.5 and is classified as MEDIUM severity. Users of code-projects Online Job Port [truncated]

MEDIUM code-projects CVE published 2026-07-04

CVE-2026-14660

A SQL injection vulnerability was found in the login.php file of Online Job Portal 1.0. The vulnerability allows remote attackers to inject malicious SQL code by manipulating the txtUser and txtPass arguments. The exploit has been made public and could be used by attackers to compromise the affected system. The vulnerability has a CVSS score of 5.5 and is classified as MEDIUM severity. The affected vendor [truncated]

LOW code-projects CVE published 2026-07-04

CVE-2026-14658

CVE-2026-14658 is a SQL injection vulnerability detected in Assessment Management 1.0. The vulnerability affects an unknown code section of the /lecturer/marking-scheme.php file. The manipulation of the smarksrange[] argument results in SQL injection. The attack can be launched remotely, and the exploit is now public. The CVSS score for this vulnerability is 2.1, indicating a low severity. The CVE was pub [truncated]

LOW code-projects CVE published 2026-07-04

CVE-2026-14657

A SQL injection vulnerability has been discovered in Assessment Management 1.0. The issue lies in the Database Query Handler of the /lecturer/marking-scheme.php file. An attacker can exploit this vulnerability remotely by manipulating the squestions[] argument. The exploit has been published and may be used. The CVSS score for this vulnerability is 2.1, indicating a low severity. The vulnerability was pub [truncated]

LOW code-projects CVE published 2026-07-04

CVE-2026-14656

CVE-2026-14656 is a cross site scripting vulnerability detected in Code-Projects Assessment Management 1.0. The vulnerability affects an unknown part of the file /admin/remove-user.php. The manipulation of the argument ID leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The CVSS score for this vulnerability is 2.1, indi [truncated]

LOW code-projects CVE published 2026-07-04

CVE-2026-14655

A low-severity cross-site scripting vulnerability has been identified in Code-Projects Assessment Management 1.0. The vulnerability affects an unknown functionality of the file admin/view-users.php and can be exploited remotely. The exploit has been made publicly available and could be used for attacks. The CVSS score for this vulnerability is 1.9, indicating a low severity. The vulnerability was publishe [truncated]

MEDIUM Code-Projects CVE published 2026-07-04

CVE-2026-14649

A SQL injection vulnerability was detected in Code-Projects Online Voting System 1.0. The impacted function is test_input in the file /saveVote.php. Performing a manipulation of the argument voterName/voterEmail/voterID/selectedCandidate results in SQL injection. The attack can be initiated remotely. This vulnerability has a CVSS score of 6.9 and a severity of MEDIUM.

LOW code-projects CVE published 2026-06-28

CVE-2026-13504

CVE-2026-13504 is a cross-site scripting vulnerability found in the Project Management System 1.0. The vulnerability affects the mail compose page, located at /mail.php, and allows an attacker to inject malicious scripts. The attack can be performed remotely, and the exploit has been publicly disclosed. The CVSS score for this vulnerability is 2, indicating a low severity. The vulnerability was published [truncated]

MEDIUM code-projects CVE published 2026-06-08

CVE-2026-11488

A SQL injection vulnerability has been discovered in the Simple Flight Ticket Booking System 1.0. The vulnerability affects an unknown part of the file checkUser.php, specifically the POST parameter handler for the Username argument. This allows for remote exploitation, and a public exploit has been disclosed.

MEDIUM code-projects CVE published 2026-06-05

CVE-2026-11342

A SQL injection vulnerability has been discovered in the Hotel and Tourism Reservation System 1.0. This vulnerability affects an unknown function of the file /details.php and can be exploited remotely by manipulating the 'room' argument. The vulnerability has been publicly disclosed and can be used by attackers. The CVSS score for this vulnerability is 5.5, indicating a medium severity.

MEDIUM code-projects CVE published 2026-06-01

CVE-2026-10262

A SQL injection vulnerability exists in the code-projects Real State Services 1.0 application, specifically within the /loginuser.php file's Login component. The Username parameter is susceptible to manipulation, allowing remote attackers to inject malicious SQL commands. The vulnerability has been publicly disclosed and proof-of-concept exploit information is available. The CVSS 4.0 vector indicates netw [truncated]

LOW code-projects CVE published 2026-06-01

CVE-2026-10209

A SQL injection vulnerability exists in the Online Hospital Management System 1.0 from code-projects. The flaw resides in the appointmentdetail.php file within the Appointment Handler component, where the editid parameter is improperly sanitized. An attacker with low privileges can manipulate this argument to inject malicious SQL commands remotely. The vulnerability has been publicly disclosed and an expl [truncated]

MEDIUM code-projects CVE published 2026-06-01

CVE-2026-10208

A SQL injection vulnerability exists in the Online Hospital Management System project. The flaw resides in the `login_user` function within `login_1.php`, where the `Username` parameter is improperly sanitized. An unauthenticated remote attacker can manipulate this argument to inject malicious SQL statements. The vulnerability has been publicly disclosed and proof-of-concept material is available. The CVS [truncated]

MEDIUM code-projects CVE published 2026-05-31

CVE-2026-10186

A SQL injection vulnerability exists in code-projects Online Hospital Management System 1.0, specifically within the /patient.php file. The editid parameter is susceptible to manipulation, allowing remote attackers to inject arbitrary SQL commands. The vulnerability has been publicly disclosed with available exploit information, increasing the risk of active exploitation. The CVSS 4.0 vector indicates net [truncated]

MEDIUM code-projects CVE published 2026-05-31

CVE-2026-10178

A SQL injection vulnerability exists in code-projects Online Music Site 1.0, specifically within the /Administrator/PHP/AdminEditAlbum.php file. The ID parameter is susceptible to manipulation, allowing remote attackers to inject arbitrary SQL commands. The vulnerability has been publicly disclosed and is rated MEDIUM severity with a CVSS score of 5.5. The weakness is classified under CWE-89 (SQL Injectio [truncated]

MEDIUM code-projects CVE published 2026-05-30

CVE-2026-10110

A SQL injection vulnerability exists in the Student Details Management System version 1.0, distributed via code-projects.org. The flaw resides in the /index.php endpoint and is reachable through manipulation of the 'roll' parameter. The attack vector is network-accessible and does not require authentication, allowing remote exploitation. The vulnerability has been publicly disclosed with available exploit details.

LOW code-projects CVE published 2026-05-25

CVE-2026-9451

A SQL injection vulnerability exists in code-projects Employee Management System 1.0, specifically in the /process/applyleaveprocess.php file. The vulnerability stems from improper sanitization of the 'ID' parameter, allowing remote attackers to inject malicious SQL commands. The CVSS 4.0 score of 2.1 (LOW severity) reflects limited privileges required and low impact on confidentiality, integrity, and ava [truncated]

LOW code-projects CVE published 2026-05-25

CVE-2026-9450

A SQL injection vulnerability exists in code-projects Employee Management System 1.0, specifically in the /psubmit.php file via the pid parameter. The vulnerability allows remote attackers to manipulate database queries. The CVSS 4.0 vector indicates network attack vector with low attack complexity, low privileges required, and no user interaction needed. The vulnerability has been publicly disclosed with [truncated]

LOW code-projects CVE published 2026-05-25

CVE-2026-9449

A SQL injection vulnerability exists in code-projects Employee Management System 1.0, affecting the /changepassemp.php file. The vulnerability allows remote attackers to manipulate SQL queries through unspecified input parameters. The CVSS 4.0 score of 2.1 reflects low severity with network attack vector, low attack complexity, and required privileges. The vulnerability was published on May 25, 2026, with [truncated]

LOW code-projects CVE published 2026-05-25

CVE-2026-9418

A cross-site scripting (XSS) vulnerability exists in code-projects Employee Management System 1.0, specifically within the /changepassemp.php file. The vulnerability stems from improper handling of the ID parameter, allowing remote attackers to inject malicious scripts. The CVSS 4.0 vector indicates network attack vector, low attack complexity, no required privileges, but requires user interaction, with p [truncated]

LOW code-projects CVE published 2026-05-25

CVE-2026-9416

A stored or reflected cross-site scripting (XSS) vulnerability exists in code-projects Employee Management System 1.0, specifically within the /myprofile.php endpoint. The vulnerability stems from improper sanitization of the 'ID' parameter, allowing remote attackers to inject malicious scripts. The CVSS 4.0 vector indicates network attack vector, low attack complexity, no required privileges, but require [truncated]

LOW code-projects CVE published 2026-04-09

CVE-2026-5834

A vulnerability was detected in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/admin_running.php. Performing a manipulation of the argument product_name results in cross site scripting. It is possible to initiate the attack remotely. The vulnerability has a CVSS score of 1.9, indicating a low severity. Users with administrative access should be aware of this vulner [truncated]

MEDIUM code-projects CVE published 2026-04-09

CVE-2026-5829

A SQL injection vulnerability was found in Simple IT Discussion Forum 1.0. The vulnerability is located in the /pages/content.php file and is caused by manipulation of the post_id argument. This allows for remote exploitation of the attack. The exploit has been publicly disclosed and may be utilized. Administrators and users should be aware of the vulnerability and take necessary steps to protect their systems.

MEDIUM code-projects CVE published 2026-04-09

CVE-2026-5828

A SQL injection vulnerability was found in the Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /functions/addcomment.php. The manipulation of the argument postid results in SQL injection. The attack may be launched remotely. This vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. Administrators and users should be aware of this vulnerability and take im [truncated]

LOW code-projects CVE published 2026-04-09

CVE-2026-5826

A flaw has been found in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the file /edit-category.php. Executing a manipulation of the argument Category can lead to cross site scripting. The attack can be launched remotely. This vulnerability has a CVSS score of 2.1 and is considered Low severity. Users should be aware of this vulnerability and take steps to mitigate it.

LOW code-projects CVE published 2026-04-09

CVE-2026-5825

A vulnerability was detected in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /delmemberinfo.php. Performing a manipulation of the argument userid results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. Security teams should review the CVE record and consider the potential impact on their systems.

MEDIUM code-projects CVE published 2026-04-09

CVE-2026-5824

A SQL injection vulnerability has been detected in Simple Laundry System 1.0. The vulnerability affects an unknown part of the file /userchecklogin.php and can be exploited remotely. This vulnerability allows attackers to inject malicious SQL code, potentially leading to unauthorized access or data manipulation. Users of Simple Laundry System 1.0 should be aware of this vulnerability and take steps to mit [truncated]

LOW code-projects CVE published 2026-04-08

CVE-2026-5806

A security vulnerability has been detected in code-projects Easy Blog Site 1.0, specifically in the /posts/update.php file. The manipulation of the argument postTitle leads to cross-site scripting (XSS). The attack may be initiated remotely. This vulnerability affects an unknown function of the file, and users of code-projects Easy Blog Site 1.0 should apply vendor remediation to prevent cross-site scripting attacks.

MEDIUM code-projects CVE published 2026-04-08

CVE-2026-5805

A SQL injection vulnerability has been identified in Easy Blog Site PHP, specifically in the /users/contact_us.php file. The vulnerability can be exploited remotely by manipulating the Name argument, potentially leading to unauthorized access to sensitive data. This issue affects users of Easy Blog Site PHP who have not updated to a patched version. The vulnerability has a CVSS score of 5.5 and is conside [truncated]

LOW code-projects CVE published 2026-04-07

CVE-2026-5705

A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown functionality of the file /booknow.php of the component Booking Endpoint. Such manipulation of the argument roomname leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This vulnerability has a CVSS score of 2.1 [truncated]

MEDIUM code-projects CVE published 2026-04-06

CVE-2026-5672

A SQL injection vulnerability has been identified in Simple IT Discussion Forum 1.0. The issue arises from the /edit-category.php file, where the cat_id argument is not properly sanitized, allowing for remote exploitation. The vulnerability has been publicly disclosed and may be used by attackers. This issue impacts administrators and users of Simple IT Discussion Forum 1.0, who should be aware of this vu [truncated]

MEDIUM code-projects CVE published 2026-04-05

CVE-2026-5565

A SQL injection vulnerability was detected in the Simple Laundry System 1.0. The issue affects an unknown functionality of the /delmemberinfo.php file in the Parameter Handler component. Manipulation of the userid argument leads to SQL injection. The attack may be launched remotely. The exploit has been publicly disclosed. This vulnerability has significant implications for the security of the affected sy [truncated]

MEDIUM code-projects CVE published 2026-03-31

CVE-2026-5198

CVE-2026-5198 is a sql injection vulnerability in code-projects Student Membership System 1.0. The impacted element is an unknown function of the file /admin/index.php of the component Admin Login. This manipulation of the argument username/password causes sql injection. Remote exploitation of the attack is possible. The vulnerability has a CVSS score of 5.5 and is considered Medium severity. Security tea [truncated]