PatchSiren

code-projects CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM code-projects CVE published 2026-04-08

CVE-2026-5805

A SQL injection vulnerability has been identified in Easy Blog Site PHP, specifically in the /users/contact_us.php file. The vulnerability can be exploited remotely by manipulating the Name argument, potentially leading to unauthorized access to sensitive data. This issue affects users of Easy Blog Site PHP who have not updated to a patched version. The vulnerability has a CVSS score of 5.5 and is conside [truncated]

LOW code-projects CVE published 2026-04-07

CVE-2026-5705

A vulnerability was identified in code-projects Online Hotel Booking 1.0. Affected by this vulnerability is an unknown functionality of the file /booknow.php of the component Booking Endpoint. Such manipulation of the argument roomname leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used. This vulnerability has a CVSS score of 2.1 [truncated]

MEDIUM code-projects CVE published 2026-04-06

CVE-2026-5672

A SQL injection vulnerability has been identified in Simple IT Discussion Forum 1.0. The issue arises from the /edit-category.php file, where the cat_id argument is not properly sanitized, allowing for remote exploitation. The vulnerability has been publicly disclosed and may be used by attackers. This issue impacts administrators and users of Simple IT Discussion Forum 1.0, who should be aware of this vu [truncated]

MEDIUM code-projects CVE published 2026-04-05

CVE-2026-5565

A SQL injection vulnerability was detected in the Simple Laundry System 1.0. The issue affects an unknown functionality of the /delmemberinfo.php file in the Parameter Handler component. Manipulation of the userid argument leads to SQL injection. The attack may be launched remotely. The exploit has been publicly disclosed. This vulnerability has significant implications for the security of the affected sy [truncated]

MEDIUM code-projects CVE published 2026-03-31

CVE-2026-5198

CVE-2026-5198 is a sql injection vulnerability in code-projects Student Membership System 1.0. The impacted element is an unknown function of the file /admin/index.php of the component Admin Login. This manipulation of the argument username/password causes sql injection. Remote exploitation of the attack is possible. The vulnerability has a CVSS score of 5.5 and is considered Medium severity. Security tea [truncated]

CRITICAL code-projects CVE published 2026-02-18

CVE-2025-70152

A critical SQL injection vulnerability exists in code-projects Community Project Scholars Tracking System 1.0, specifically in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints are vulnerable because they lack authentication checks and directly concatenate user-supplied POST parameters into SQL queries without validation or parameterization, allowing for [truncated]

HIGH Code Projects CVE published 2026-02-18

CVE-2025-70151

CVE-2025-70151 is a high-severity vulnerability in the Scholars Tracking System 1.0 that allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The vulnerability exists in the update_profile_picture.php and upload_picture.php endpoints, which store uploaded files in a web-accessible uploads/ directory using the original, user-supplied filename without validating th [truncated]

MEDIUM code-projects CVE published 2026-01-01

CVE-2025-15410

A vulnerability was identified in code-projects Online Guitar Store 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument L_email leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. This SQL injection vulnerability in the /login.php file of Online Guitar Store 1.0 can be ex [truncated]

MEDIUM code-projects CVE published 2026-01-01

CVE-2025-15409

A vulnerability was determined in code-projects Online Guitar Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/Delete_product.php. Executing a manipulation of the argument del_pro can lead to sql injection. The attack may be performed from remote. This SQL injection vulnerability in Online Guitar Store 1.0 allows remote attackers to potentially extract or modify sen [truncated]

MEDIUM code-projects CVE published 2026-01-01

CVE-2025-15408

A vulnerability was found in code-projects Online Guitar Store 1.0. Affected is an unknown function of the file /admin/Create_product.php. Performing a manipulation of the argument dre_title results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This SQL injection vulnerability in the /admin/Create_product.php file of code-projects [truncated]

MEDIUM code-projects CVE published 2026-01-01

CVE-2025-15407

A vulnerability was found in the Online Guitar Store 1.0, impacting an unknown function in the /admin/Create_category.php file. The manipulation of the dre_Ctitle argument leads to SQL injection, which can be executed remotely. The exploit has been publicly disclosed and may be used. Defenders should assess exposure and prioritize verification and potential patching. This SQL injection vulnerability can l [truncated]