5.1

CVSS4.0

CVE-2025-13245 - code-projects Student Information System editprofile.php cross site scripting

A vulnerability was identified in code-projects Student Information System 2.0. The impacted element is an unknown function of the file /editprofile.php. Such manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be use…

πŸ“… Published: Nov. 16, 2025, 9:02 a.m. πŸ”„ Last Modified: Nov. 19, 2025, 1:17 p.m.

5.3

CVSS4.0

CVE-2025-13244 - code-projects Student Information System register.php cross site scripting

A vulnerability was determined in code-projects Student Information System 2.0. The affected element is an unknown function of the file /register.php. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be ut…

πŸ“… Published: Nov. 16, 2025, 8:32 a.m. πŸ”„ Last Modified: Nov. 19, 2025, 1:17 p.m.

5.3

CVSS4.0

CVE-2025-13243 - code-projects Student Information System editprofile.php sql injection

A vulnerability was found in code-projects Student Information System 2.0. Impacted is an unknown function of the file /editprofile.php. The manipulation results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.

πŸ“… Published: Nov. 16, 2025, 8:02 a.m. πŸ”„ Last Modified: Nov. 19, 2025, 1:18 p.m.

6.9

CVSS4.0

CVE-2025-13242 - code-projects Student Information System register.php sql injection

A vulnerability has been found in code-projects Student Information System 2.0. This issue affects some unknown processing of the file /register.php. The manipulation leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be u…

πŸ“… Published: Nov. 16, 2025, 7:32 a.m. πŸ”„ Last Modified: Nov. 19, 2025, 1:18 p.m.

6.9

CVSS4.0

CVE-2025-13241 - code-projects Student Information System index.php sql injection

A flaw has been found in code-projects Student Information System 2.0. This vulnerability affects unknown code of the file /index.php. Executing manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.

πŸ“… Published: Nov. 16, 2025, 7:02 a.m. πŸ”„ Last Modified: Jan. 7, 2026, 4:55 p.m.

6.9

CVSS4.0

CVE-2025-13240 - code-projects Student Information System searchquery.php sql injection

A vulnerability was detected in code-projects Student Information System 2.0. This affects an unknown part of the file /searchquery.php. Performing manipulation of the argument s results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.

πŸ“… Published: Nov. 16, 2025, 6:32 a.m. πŸ”„ Last Modified: Jan. 7, 2026, 4:54 p.m.

5.3

CVSS4.0

CVE-2025-13239 - Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution submit_checkout behavioral wo…

A security vulnerability has been detected in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution 5. Affected by this issue is some unknown functionality of the file /submit_checkout. Such manipulation of the argument order_total_amount/cart_total_amount leads to enforcement of be…

πŸ“… Published: Nov. 16, 2025, 6:02 a.m. πŸ”„ Last Modified: Nov. 20, 2025, 8:59 p.m.

5.3

CVSS4.0

CVE-2025-13238 - Bdtask Flight Booking Software Edit Profile edit unrestricted upload

A weakness has been identified in Bdtask Flight Booking Software 4. Affected by this vulnerability is an unknown functionality of the file /agent/profile/edit of the component Edit Profile Page. This manipulation causes unrestricted upload. The attack may be initiated remotely. The exploit has been…

πŸ“… Published: Nov. 16, 2025, 5:32 a.m. πŸ”„ Last Modified: Feb. 24, 2026, 7:16 a.m.

6.9

CVSS4.0

CVE-2025-13237 - itsourcecode Inventory Management System LogSignModal.PHP sql injection

A security flaw has been discovered in itsourcecode Inventory Management System 1.0. Affected is an unknown function of the file /LogSignModal.PHP. The manipulation of the argument U_USERNAME results in sql injection. The attack can be launched remotely. The exploit has been released to the public …

πŸ“… Published: Nov. 16, 2025, 5:02 a.m. πŸ”„ Last Modified: Nov. 18, 2025, 7:59 p.m.

7.5

CVSS3.1

CVE-2025-12482 - Booking for Appointments and Events Calendar – Amelia <= 1.2.35 - Unauthenticated SQL Injection via…

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the β€˜search’ parameter in all versions up to, and including, 1.2.35 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL qu…

πŸ“… Published: Nov. 16, 2025, 4:17 a.m. πŸ”„ Last Modified: April 22, 2026, 12:45 a.m.
Total resulsts: 346529
Page 2736 of 34,653
Β« previous page Β» next page
Filters