These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A SQL injection vulnerability exists in the Employee Management System 1.0, specifically in the /process/aprocess.php file of the Admin Login Endpoint. The manipulation of the 'mailuid' argument can lead to SQL injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. This vulnerability could allow attackers to execute arbitrary SQL queries, potentially lead [truncated]
The CVE-2026-19378 vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the file /user/CommentSave.php, leading to cross-site scripting. The attack can be launched remotely. Users should verify the existence of this vulnerability and apply patches or mitigations as necessary. This includes administrators, security teams, and operators who may b [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-09T10:17:10.387Z and has not been modified since then. CVE-2026-19345 is a missing authorization vulnerability in Task Management System 1.0, affecting the UpdateTaskStatus.php file. The vulnerability allows remote attackers to manipulate task status without proper authorization, potentially impacti [truncated]
CVE-2026-19344 is a SQL injection vulnerability in the /user/comment_count_user.php file of the Task Management System 1.0 by code-projects. The vulnerability allows for remote attacks and has been publicly disclosed. The CVSS score is 5.5, indicating a medium severity level. This vulnerability can be exploited remotely, and attackers can manipulate the task_id argument to inject malicious SQL code. The a [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-09T08:16:47.710Z and has not been modified since then. The vulnerability affects Code-projects Task Management System 1.0, specifically an unknown functionality of the file /admin/AdminLogin.php, allowing for SQL injection through manipulation of the email and password arguments. This could enable a [truncated]
The Task Management System 1.0, developed by code-projects, contains a vulnerability in its login functionality located in the /index.php file. This vulnerability, tracked as CVE-2026-19342, is caused by improper authentication when the Password argument is manipulated, allowing for remote exploitation. The affected component is the login function, which is a critical part of the system. The vulnerability [truncated]
Organizations should be aware of a Cross Site Scripting (XSS) vulnerability in code-projects Blood System 1.0, specifically in the /don.php file via the city field. This vulnerability has a CVSS score of 6.1 and is classified as MEDIUM severity. The CVE record was published on 2026-07-30T21:16:51.777Z and has not been modified since then. Affected organizations should review and apply patches or workaroun [truncated]
A vulnerability has been found in code-projects Online Examination System 1.0. This vulnerability affects unknown code of the file /account.php?q=quiz. Such manipulation of the argument eid/n/t leads to cross site scripting. The attack can be launched remotely. Users of code-projects Online Examination System 1.0 should be aware of this cross site scripting vulnerability and take steps to mitigate it. The [truncated]
A SQL injection vulnerability was found in the Login Form of Hospital Bed Management System 1.0. The vulnerability is caused by improper handling of the Username argument, allowing an attacker to inject malicious SQL code. This can lead to unauthorized access to sensitive data. Remote exploitation of this vulnerability is possible. The CVSS score for this vulnerability is 5.5, indicating a medium severity [truncated]
A security vulnerability has been detected in code-projects Online Job Portal 1.0. This impacts an unknown function of the file /Admin/DetailJob.php. The manipulation leads to cross site scripting. The attack is possible to be carried out remotely. The vulnerability is a cross site scripting (XSS) issue in the /Admin/DetailJob.php file of code-projects Online Job Portal 1.0. Users of code-projects Online [truncated]
A weakness has been identified in code-projects Online Job Portal 1.0, specifically in the /JobSeekerInsert.php file. This affects an unknown function, allowing for unrestricted file upload through manipulation of the txtFile argument. The attack can be executed remotely, and the exploit has been made available to the public. Users of code-projects Online Job Portal 1.0 should be aware of this vulnerabili [truncated]
A security flaw has been discovered in Code-projects Online Job Portal up to 1.0. The impacted element is an unknown function of the file /Admin/DeleteUser.php. Performing a manipulation results in SQL injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. This vulnerability allows remote attackers to inject malicious SQL code, po [truncated]
A vulnerability was identified in code-projects Online Job Portal 1.0, specifically in the /Admin/EditUser.php file. The vulnerability allows for SQL injection attacks through manipulation of the UserId argument. The attack can be launched remotely, and the exploit is publicly available. This vulnerability has a CVSS score of 5.5 and is classified as MEDIUM severity. Users of code-projects Online Job Port [truncated]
A SQL injection vulnerability was found in the login.php file of Online Job Portal 1.0. The vulnerability allows remote attackers to inject malicious SQL code by manipulating the txtUser and txtPass arguments. The exploit has been made public and could be used by attackers to compromise the affected system. The vulnerability has a CVSS score of 5.5 and is classified as MEDIUM severity. The affected vendor [truncated]
CVE-2026-14658 is a SQL injection vulnerability detected in Assessment Management 1.0. The vulnerability affects an unknown code section of the /lecturer/marking-scheme.php file. The manipulation of the smarksrange[] argument results in SQL injection. The attack can be launched remotely, and the exploit is now public. The CVSS score for this vulnerability is 2.1, indicating a low severity. The CVE was pub [truncated]
A SQL injection vulnerability has been discovered in Assessment Management 1.0. The issue lies in the Database Query Handler of the /lecturer/marking-scheme.php file. An attacker can exploit this vulnerability remotely by manipulating the squestions[] argument. The exploit has been published and may be used. The CVSS score for this vulnerability is 2.1, indicating a low severity. The vulnerability was pub [truncated]
CVE-2026-14656 is a cross site scripting vulnerability detected in Code-Projects Assessment Management 1.0. The vulnerability affects an unknown part of the file /admin/remove-user.php. The manipulation of the argument ID leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The CVSS score for this vulnerability is 2.1, indi [truncated]
A low-severity cross-site scripting vulnerability has been identified in Code-Projects Assessment Management 1.0. The vulnerability affects an unknown functionality of the file admin/view-users.php and can be exploited remotely. The exploit has been made publicly available and could be used for attacks. The CVSS score for this vulnerability is 1.9, indicating a low severity. The vulnerability was publishe [truncated]
A SQL injection vulnerability was detected in Code-Projects Online Voting System 1.0. The impacted function is test_input in the file /saveVote.php. Performing a manipulation of the argument voterName/voterEmail/voterID/selectedCandidate results in SQL injection. The attack can be initiated remotely. This vulnerability has a CVSS score of 6.9 and a severity of MEDIUM.
CVE-2026-13504 is a cross-site scripting vulnerability found in the Project Management System 1.0. The vulnerability affects the mail compose page, located at /mail.php, and allows an attacker to inject malicious scripts. The attack can be performed remotely, and the exploit has been publicly disclosed. The CVSS score for this vulnerability is 2, indicating a low severity. The vulnerability was published [truncated]
A SQL injection vulnerability has been discovered in the Simple Flight Ticket Booking System 1.0. The vulnerability affects an unknown part of the file checkUser.php, specifically the POST parameter handler for the Username argument. This allows for remote exploitation, and a public exploit has been disclosed.
A SQL injection vulnerability has been discovered in the Hotel and Tourism Reservation System 1.0. This vulnerability affects an unknown function of the file /details.php and can be exploited remotely by manipulating the 'room' argument. The vulnerability has been publicly disclosed and can be used by attackers. The CVSS score for this vulnerability is 5.5, indicating a medium severity.
A SQL injection vulnerability exists in the code-projects Real State Services 1.0 application, specifically within the /loginuser.php file's Login component. The Username parameter is susceptible to manipulation, allowing remote attackers to inject malicious SQL commands. The vulnerability has been publicly disclosed and proof-of-concept exploit information is available. The CVSS 4.0 vector indicates netw [truncated]
A SQL injection vulnerability exists in the Online Hospital Management System 1.0 from code-projects. The flaw resides in the appointmentdetail.php file within the Appointment Handler component, where the editid parameter is improperly sanitized. An attacker with low privileges can manipulate this argument to inject malicious SQL commands remotely. The vulnerability has been publicly disclosed and an expl [truncated]
A SQL injection vulnerability exists in the Online Hospital Management System project. The flaw resides in the `login_user` function within `login_1.php`, where the `Username` parameter is improperly sanitized. An unauthenticated remote attacker can manipulate this argument to inject malicious SQL statements. The vulnerability has been publicly disclosed and proof-of-concept material is available. The CVS [truncated]
A SQL injection vulnerability exists in code-projects Online Hospital Management System 1.0, specifically within the /patient.php file. The editid parameter is susceptible to manipulation, allowing remote attackers to inject arbitrary SQL commands. The vulnerability has been publicly disclosed with available exploit information, increasing the risk of active exploitation. The CVSS 4.0 vector indicates net [truncated]
A SQL injection vulnerability exists in code-projects Online Music Site 1.0, specifically within the /Administrator/PHP/AdminEditAlbum.php file. The ID parameter is susceptible to manipulation, allowing remote attackers to inject arbitrary SQL commands. The vulnerability has been publicly disclosed and is rated MEDIUM severity with a CVSS score of 5.5. The weakness is classified under CWE-89 (SQL Injectio [truncated]
A SQL injection vulnerability exists in the Student Details Management System version 1.0, distributed via code-projects.org. The flaw resides in the /index.php endpoint and is reachable through manipulation of the 'roll' parameter. The attack vector is network-accessible and does not require authentication, allowing remote exploitation. The vulnerability has been publicly disclosed with available exploit details.
A SQL injection vulnerability exists in code-projects Employee Management System 1.0, specifically in the /process/applyleaveprocess.php file. The vulnerability stems from improper sanitization of the 'ID' parameter, allowing remote attackers to inject malicious SQL commands. The CVSS 4.0 score of 2.1 (LOW severity) reflects limited privileges required and low impact on confidentiality, integrity, and ava [truncated]
A SQL injection vulnerability exists in code-projects Employee Management System 1.0, specifically in the /psubmit.php file via the pid parameter. The vulnerability allows remote attackers to manipulate database queries. The CVSS 4.0 vector indicates network attack vector with low attack complexity, low privileges required, and no user interaction needed. The vulnerability has been publicly disclosed with [truncated]
A SQL injection vulnerability exists in code-projects Employee Management System 1.0, affecting the /changepassemp.php file. The vulnerability allows remote attackers to manipulate SQL queries through unspecified input parameters. The CVSS 4.0 score of 2.1 reflects low severity with network attack vector, low attack complexity, and required privileges. The vulnerability was published on May 25, 2026, with [truncated]
A cross-site scripting (XSS) vulnerability exists in code-projects Employee Management System 1.0, specifically within the /changepassemp.php file. The vulnerability stems from improper handling of the ID parameter, allowing remote attackers to inject malicious scripts. The CVSS 4.0 vector indicates network attack vector, low attack complexity, no required privileges, but requires user interaction, with p [truncated]
A stored or reflected cross-site scripting (XSS) vulnerability exists in code-projects Employee Management System 1.0, specifically within the /myprofile.php endpoint. The vulnerability stems from improper sanitization of the 'ID' parameter, allowing remote attackers to inject malicious scripts. The CVSS 4.0 vector indicates network attack vector, low attack complexity, no required privileges, but require [truncated]
A vulnerability was detected in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/admin_running.php. Performing a manipulation of the argument product_name results in cross site scripting. It is possible to initiate the attack remotely. The vulnerability has a CVSS score of 1.9, indicating a low severity. Users with administrative access should be aware of this vulner [truncated]
A SQL injection vulnerability was found in Simple IT Discussion Forum 1.0. The vulnerability is located in the /pages/content.php file and is caused by manipulation of the post_id argument. This allows for remote exploitation of the attack. The exploit has been publicly disclosed and may be utilized. Administrators and users should be aware of the vulnerability and take necessary steps to protect their systems.
A SQL injection vulnerability was found in the Simple IT Discussion Forum 1.0. The affected element is an unknown function of the file /functions/addcomment.php. The manipulation of the argument postid results in SQL injection. The attack may be launched remotely. This vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. Administrators and users should be aware of this vulnerability and take im [truncated]
A flaw has been found in code-projects Simple IT Discussion Forum 1.0. This issue affects some unknown processing of the file /edit-category.php. Executing a manipulation of the argument Category can lead to cross site scripting. The attack can be launched remotely. This vulnerability has a CVSS score of 2.1 and is considered Low severity. Users should be aware of this vulnerability and take steps to mitigate it.
A vulnerability was detected in code-projects Simple Laundry System 1.0. This vulnerability affects unknown code of the file /delmemberinfo.php. Performing a manipulation of the argument userid results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. Security teams should review the CVE record and consider the potential impact on their systems.
A SQL injection vulnerability has been detected in Simple Laundry System 1.0. The vulnerability affects an unknown part of the file /userchecklogin.php and can be exploited remotely. This vulnerability allows attackers to inject malicious SQL code, potentially leading to unauthorized access or data manipulation. Users of Simple Laundry System 1.0 should be aware of this vulnerability and take steps to mit [truncated]
A security vulnerability has been detected in code-projects Easy Blog Site 1.0, specifically in the /posts/update.php file. The manipulation of the argument postTitle leads to cross-site scripting (XSS). The attack may be initiated remotely. This vulnerability affects an unknown function of the file, and users of code-projects Easy Blog Site 1.0 should apply vendor remediation to prevent cross-site scripting attacks.
A SQL injection vulnerability has been identified in Easy Blog Site PHP, specifically in the /users/contact_us.php file. The vulnerability can be exploited remotely by manipulating the Name argument, potentially leading to unauthorized access to sensitive data. This issue affects users of Easy Blog Site PHP who have not updated to a patched version. The vulnerability has a CVSS score of 5.5 and is conside [truncated]
A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown functionality of the file /booknow.php of the component Booking Endpoint. Such manipulation of the argument roomname leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This vulnerability has a CVSS score of 2.1 [truncated]
A SQL injection vulnerability has been identified in Simple IT Discussion Forum 1.0. The issue arises from the /edit-category.php file, where the cat_id argument is not properly sanitized, allowing for remote exploitation. The vulnerability has been publicly disclosed and may be used by attackers. This issue impacts administrators and users of Simple IT Discussion Forum 1.0, who should be aware of this vu [truncated]
A SQL injection vulnerability was detected in the Simple Laundry System 1.0. The issue affects an unknown functionality of the /delmemberinfo.php file in the Parameter Handler component. Manipulation of the userid argument leads to SQL injection. The attack may be launched remotely. The exploit has been publicly disclosed. This vulnerability has significant implications for the security of the affected sy [truncated]
CVE-2026-5198 is a sql injection vulnerability in code-projects Student Membership System 1.0. The impacted element is an unknown function of the file /admin/index.php of the component Admin Login. This manipulation of the argument username/password causes sql injection. Remote exploitation of the attack is possible. The vulnerability has a CVSS score of 5.5 and is considered Medium severity. Security tea [truncated]