Vulnerabilities (CVE)

Filtered by vendor Janobe Subscribe
Total 169 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-48245 1 Janobe 1 Vehicle Management System 2026-07-05 N/A 7.2 HIGH
Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in various administrative actions, such as booking a vehicle or confirming a booking. The affected parameters include "Booking ID", "Action Name", and "Payment Confirmation ID", which are present in /newvehicle.php and /newdriver.php.
CVE-2026-36920 1 Janobe 1 Online Reviewer System 2026-06-17 N/A 2.7 LOW
Sourcecodester Online Reviewer System v1.0 is vulnerable to SQL Injection in the file /system/system/admins/assessments/examproper/questions-view.php.
CVE-2026-36919 1 Janobe 1 Online Reviewer System 2026-06-17 N/A 2.7 LOW
Sourcecodester Online Reviewer System v1.0 is vulnerale to SQL Injection in the file /system/system/admins/assessments/examproper/exam-update.php.
CVE-2026-36236 1 Janobe 1 Engineers Online Portal 2026-06-17 N/A 9.8 CRITICAL
SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter.
CVE-2026-2090 1 Janobe 1 Online Class Record System 2026-06-17 7.5 HIGH 7.3 HIGH
A vulnerability was determined in SourceCodester Online Class Record System 1.0. This issue affects some unknown processing of the file /admin/message/search.php. Executing a manipulation of the argument term can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2026-2089 1 Janobe 1 Online Class Record System 2026-06-17 7.5 HIGH 7.3 HIGH
A vulnerability was found in SourceCodester Online Class Record System 1.0. This vulnerability affects unknown code of the file /admin/subject/controller.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
CVE-2026-2087 1 Janobe 1 Online Class Record System 2026-06-17 7.5 HIGH 7.3 HIGH
A flaw has been found in SourceCodester Online Class Record System 1.0. Affected by this issue is some unknown functionality of the file /admin/login.php. This manipulation of the argument user_email causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
CVE-2026-1154 1 Janobe 1 E-learning System 2026-06-17 5.0 MEDIUM 4.3 MEDIUM
A flaw has been found in SourceCodester E-Learning System 1.0. This impacts an unknown function of the file /admin/modules/lesson/index.php of the component Lesson Module Handler. Executing a manipulation of the argument Title/Description can lead to basic cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.
CVE-2025-9706 1 Janobe 1 Water Billing System 2026-06-17 7.5 HIGH 7.3 HIGH
A security vulnerability has been detected in SourceCodester Water Billing System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
CVE-2025-9705 1 Janobe 1 Water Billing System 2026-06-17 7.5 HIGH 7.3 HIGH
A weakness has been identified in SourceCodester Water Billing System 1.0. Affected is an unknown function of the file /paybill.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.
CVE-2025-9704 1 Janobe 1 Water Billing System 2026-06-17 7.5 HIGH 7.3 HIGH
A security flaw has been discovered in SourceCodester Water Billing System 1.0. This impacts an unknown function of the file /viewbill.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be exploited.
CVE-2025-9700 1 Janobe 1 Online Book Store 2026-06-17 7.5 HIGH 7.3 HIGH
A flaw has been found in SourceCodester Online Book Store 1.0. This issue affects some unknown processing of the file /publisher_list.php. This manipulation of the argument pubid causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.
CVE-2025-9660 1 Janobe 1 Bakeshop Online Ordering System 2026-06-17 7.5 HIGH 7.3 HIGH
A vulnerability was found in SourceCodester Bakeshop Online Ordering System 1.0. The impacted element is an unknown function of the file /passwordrecover.php. Performing manipulation of the argument phonenumber results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
CVE-2025-2377 1 Janobe 1 Vehicle Management System 2026-06-17 4.0 MEDIUM 3.5 LOW
A vulnerability was found in SourceCodester Vehicle Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /confirmbooking.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions contradicting product names.
CVE-2025-1590 1 Janobe 1 E-learning System 2026-06-17 5.8 MEDIUM 4.7 MEDIUM
A vulnerability was found in SourceCodester E-Learning System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/modules/lesson/index.php of the component List of Lessons Page. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely.
CVE-2025-1589 1 Janobe 1 E-learning System 2026-06-17 5.0 MEDIUM 4.3 MEDIUM
A vulnerability was found in SourceCodester E-Learning System 1.0 and classified as problematic. This issue affects some unknown processing of the file /register.php of the component User Registration Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely.
CVE-2025-1192 1 Janobe 1 Multi Restaurant Table Reservation System 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in SourceCodester Multi Restaurant Table Reservation System 1.0. It has been classified as critical. Affected is an unknown function of the file select-menu.php. The manipulation of the argument table leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-1191 1 Janobe 1 Multi Restaurant Table Reservation System 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was found in SourceCodester Multi Restaurant Table Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file /dashboard/approve-reject.php. The manipulation of the argument breject_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-13343 1 Janobe 1 Interview Management System 2026-06-17 4.0 MEDIUM 3.5 LOW
A security flaw has been discovered in SourceCodester Interview Management System 1.0. Affected is an unknown function of the file /editQuestion.php. The manipulation of the argument Question results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited.
CVE-2025-13257 1 Janobe 1 Inventory Management System 2026-06-17 7.5 HIGH 7.3 HIGH
A security vulnerability has been detected in itsourcecode Inventory Management System 1.0. The affected element is an unknown function of the file /admin/user/index.php?view=edit. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.