<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – PHP</title>
  <link>https://cvedaily.com/pages/tags/php.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/php.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – PHP</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:27 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-7888 – Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize()...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7888</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7888</guid>
    <pubDate>Wed, 03 Jun 2026 19:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7888</strong></p>
  <p>Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes restriction. An unauthenticated attacker may trigger arbitrary PHP object instantiation if a malicious serialized payload has been placed in the database. Thanks XananasX7 and Sanjorn Keeratirungsan (dizconnect) for both independ…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7888">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10704 – A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Af...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10704</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10704</guid>
    <pubDate>Wed, 03 Jun 2026 02:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10704</strong></p>
  <p>A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrative Control Panel. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10704">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10694 – A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10694</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10694</guid>
    <pubDate>Wed, 03 Jun 2026 01:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10694</strong></p>
  <p>A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function include of the file /index.php. The manipulation of the argument page results in file inclusion. The attack can be launched remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10694">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10624 – A vulnerability has been found in SourceCodester Human Resource Management 1.0. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10624</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10624</guid>
    <pubDate>Tue, 02 Jun 2026 21:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10624</strong></p>
  <p>A vulnerability has been found in SourceCodester Human Resource Management 1.0. Affected by this vulnerability is an unknown functionality of the file /detailview.php of the component Employee View Page. Such manipulation of the argument employeeid leads to improper control of resource identifiers. The attack may be performed from remote. The exploit has been disclosed to the public and may be us…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-99</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10624">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10620 – A flaw has been found in code-projects Student Admission System 1.0. Affected is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10620</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10620</guid>
    <pubDate>Tue, 02 Jun 2026 21:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10620</strong></p>
  <p>A flaw has been found in code-projects Student Admission System 1.0. Affected is an unknown function of the file /index.php. This manipulation of the argument eid/did causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10620">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10608 – A security flaw has been discovered in DedeCMS 5.7.88. This affects the function...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10608</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10608</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10608</strong></p>
  <p>A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the file /plus/carbuyaction.php. The manipulation of the argument postname/des results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10608">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10607 – A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the fu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10607</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10607</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10607</strong></p>
  <p>A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspecialchars of the file /plus/flink.php. The manipulation of the argument msg leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10607">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40571 – NamelessMC is website software for Minecraft servers. In version 2.2.4, `core/cl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40571</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40571</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40571</strong></p>
  <p>NamelessMC is website software for Minecraft servers. In version 2.2.4, `core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private-profile visibility. This means that authenticated low-privileged users can add reactions to private or blocking profile posts. Version 2.2.5 contains a patch.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40571">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40314 – NamelessMC is website software for Minecraft servers. In version 2.2.4,`core/cla...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40314</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40314</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40314</strong></p>
  <p>NamelessMC is website software for Minecraft servers. In version 2.2.4,`core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private-profile visibility. `modules/Core/queries/reactions.php` allows unauthenticated GET requests for reaction details. This means that unauthenticated visitors can read reaction participants and timestamp…</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40314">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35447 – NamelessMC is website software for Minecraft servers. In version 2.2.4, the prof...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35447</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35447</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35447</strong></p>
  <p>NamelessMC is website software for Minecraft servers. In version 2.2.4, the profile page (modules/Core/pages/profile.php) processes wall post submissions and replies before verifying whether the viewer is authorized to access the profile. This allows any user with the profile.post permission to write wall posts to private or blocking profiles. Additionally, the reply branch does not verify that t…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-201</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35447">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-35443 – NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35443</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35443</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-35443</strong></p>
  <p>NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/classes/ForumPostReactionContext.php` only verifies that the caller can view the forum, but it does not re-enforce topic-level `view_other_topics` authorization. As a result, in forums where users may enter the forum but may only view their own topics, reactions can still be read and modified on other users' to…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35443">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10606 – A vulnerability was determined in DedeCMS 5.7.88. The affected element is the fu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10606</guid>
    <pubDate>Tue, 02 Jun 2026 17:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10606</strong></p>
  <p>A vulnerability was determined in DedeCMS 5.7.88. The affected element is the function TrimMsg of the file /plus/feedback.php of the component Feedback Handler. Executing a manipulation of the argument msg can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33398 – NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33398</guid>
    <pubDate>Tue, 02 Jun 2026 16:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33398</strong></p>
  <p>NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/pages/forum/get_quotes.php` only checks whether the caller is logged in, then reads a post by attacker-controlled `post` ID and returns its content. The backend helper in `modules/Forum/classes/Forum.php` does not enforce forum or topic ACLs. In contrast, the normal topic page in `modules/Forum/pages/forum/view…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39553 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39553</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39553</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes WaveRide allows PHP Local File Inclusion.  This issue affects WaveRide: from n/a through 1.4.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-39552 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-39552</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-39552</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-39552</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Code Supply Co. Blueprint allows PHP Local File Inclusion.  This issue affects Blueprint: from n/a before 1.1.5.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39552">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-32250 – NamelessMC is website software for Minecraft servers. A Reflected Cross-Site Scr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32250</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32250</strong></p>
  <p>NamelessMC is website software for Minecraft servers. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in version 2.2.4 in the id parameter of the endpoint `/index.php?route=/queries/user/`. The application reflects user-supplied input from the id parameter into the HTML response without proper sanitization or output encoding. An attacker can craft a malicious URL containing Ja…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-69369 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69369</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69369</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-69369</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Racquet allows PHP Local File Inclusion.  This issue affects Racquet: from n/a through 1.12.0.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69369">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68886 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68886</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68886</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68886</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in androThemes Cookiteer allows PHP Local File Inclusion.  This issue affects Cookiteer: from n/a through 1.4.8.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68886">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58897 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58897</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58897</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58897</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Fermentio allows PHP Local File Inclusion.  This issue affects Fermentio: from n/a through 1.5.0.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58897">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58707 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58707</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58707</guid>
    <pubDate>Tue, 02 Jun 2026 14:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58707</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Spin allows PHP Local File Inclusion.  This issue affects Spin: from n/a through 1.8.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58707">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58705 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58705</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58705</guid>
    <pubDate>Tue, 02 Jun 2026 12:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58705</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Crafti allows PHP Local File Inclusion.  This issue affects Crafti: from n/a through 1.12.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58705">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58024 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58024</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58024</guid>
    <pubDate>Tue, 02 Jun 2026 12:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58024</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in UnboundStudio Accordion FAQ allows PHP Local File Inclusion.  This issue affects Accordion FAQ: from n/a through 2.2.1.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58024">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53440 – Improper Control of Filename for Include/Require Statement in PHP Program ('PHP ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53440</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53440</guid>
    <pubDate>Tue, 02 Jun 2026 12:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53440</strong></p>
  <p>Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Confidant allows PHP Local File Inclusion.  This issue affects Confidant: from n/a through 1.4.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53440">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10581 – A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10581</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10581</guid>
    <pubDate>Tue, 02 Jun 2026 04:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10581</strong></p>
  <p>A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decode of the file /plus/download.php?open=1. This manipulation of the argument Link causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10581">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10568 – A vulnerability was detected in itsourcecode Fees Management System 1.0. Affecte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10568</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10568</guid>
    <pubDate>Tue, 02 Jun 2026 03:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10568</strong></p>
  <p>A vulnerability was detected in itsourcecode Fees Management System 1.0. Affected is an unknown function of the file /manage_payment.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10568">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10100 – The Simple Custom Login Page plugin for WordPress is vulnerable to Stored Cross-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10100</guid>
    <pubDate>Tue, 02 Jun 2026 03:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10100</strong></p>
  <p>The Simple Custom Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color settings fields (Page Background, Form Background, Text Color, Link Color) in versions up to and including 1.0.3. This is due to insufficient input sanitization of the color option values (they were registered with register_setting() and stored via the Settings API/update_option() with no…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10559 – A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10559</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10559</guid>
    <pubDate>Tue, 02 Jun 2026 02:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10559</strong></p>
  <p>A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is an unknown function of the file /index.php. Executing a manipulation of the argument page can lead to file inclusion. The attack may be performed from remote. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10559">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10558 – A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Imp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10558</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10558</guid>
    <pubDate>Tue, 02 Jun 2026 02:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10558</strong></p>
  <p>A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument page results in file inclusion. The attack is possible to be carried out remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10558">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10302 – A flaw has been found in itsourcecode Fees Management System 1.0. The impacted e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10302</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10302</guid>
    <pubDate>Tue, 02 Jun 2026 00:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10302</strong></p>
  <p>A flaw has been found in itsourcecode Fees Management System 1.0. The impacted element is an unknown function of the file /manage_fee.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10302">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10301 – A vulnerability was detected in itsourcecode Fees Management System 1.0. The aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10301</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10301</guid>
    <pubDate>Tue, 02 Jun 2026 00:16:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10301</strong></p>
  <p>A vulnerability was detected in itsourcecode Fees Management System 1.0. The affected element is an unknown function of the file index.php. Performing a manipulation of the argument page results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10301">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10299 – A weakness has been identified in code-projects Online Hospital Management Syste...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10299</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10299</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10299</strong></p>
  <p>A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. This manipulation of the argument delid causes improper control of resource identifiers. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-99</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10299">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10297 – A vulnerability was identified in itsourcecode Fees Management System 1.0. This ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10297</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10297</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10297</strong></p>
  <p>A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown part of the file /manage_course.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10297">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10296 – A vulnerability was determined in itsourcecode Fees Management System 1.0. Affec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10296</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10296</guid>
    <pubDate>Mon, 01 Jun 2026 23:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10296</strong></p>
  <p>A vulnerability was determined in itsourcecode Fees Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10296">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49491 – Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49491</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49491</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49491</strong></p>
  <p>Pixa Bank 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to extract sensitive data by injecting SQL code into the 'rib' parameter. Attackers can send POST requests to the agence-ajax.php endpoint with UNION-based SQL payloads to retrieve user information including names, email addresses, and phone numbers from the database.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49491">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10290 – A weakness has been identified in code-projects Hotel and Tourism Reservation Sy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10290</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10290</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10290</strong></p>
  <p>A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tour.php of the component GET Parameter Handler. Executing a manipulation of the argument tour can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10290">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25434 – WP AutoSuggest 0.24 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25434</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25434</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25434</strong></p>
  <p>WP AutoSuggest 0.24 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the wpas_keys parameter. Attackers can send GET requests to autosuggest.php with crafted wpas_keys values to extract sensitive database information from WordPress posts and other tables.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25434">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25433 – Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25433</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25433</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25433</strong></p>
  <p>Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through the categoryid parameter. Attackers can send GET requests to index.php with crafted categoryid values in the com_jephotogallery component to execute arbitrary SQL queries and retrieve sensitive data like usernam…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25433">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25430 – Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25430</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25430</strong></p>
  <p>Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the eGeqIdEquipe parameter. Attackers can send GET requests to the egeq.php endpoint with crafted SQL payloads to extract sensitive database information including version details and other data.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25429 – Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25429</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25429</strong></p>
  <p>Paroiciel 11.20 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the zProIdPro parameter. Attackers can send GET requests to zpro.php with crafted SQL payloads in the zProIdPro parameter to extract sensitive database information including usernames, databases, and version details.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25428 – Paroiciel 11.20 contains an SQL injection vulnerability that allows unauthentica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25428</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25428</guid>
    <pubDate>Mon, 01 Jun 2026 22:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25428</strong></p>
  <p>Paroiciel 11.20 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the tRecIdListe parameter. Attackers can send GET requests to the trec.php endpoint with crafted SQL payloads to extract database information including table and column names.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25428">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10289 – A security flaw has been discovered in code-projects Hotel and Tourism Reservati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10289</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10289</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10289</strong></p>
  <p>A security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0. Impacted is an unknown function of the file /ht/tour.php. Performing a manipulation of the argument name /email /people /number results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10289">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10288 – A vulnerability was identified in code-projects Hotel and Tourism Reservation Sy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10288</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10288</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10288</strong></p>
  <p>A vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This issue affects the function password_verify of the file /admin/login.php of the component Admin Login. Such manipulation of the argument Password leads to improper authentication. It is possible to launch the attack remotely. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10288">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10287 – A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10287</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10287</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10287</strong></p>
  <p>A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get_headers of the file /index.php. This manipulation of the argument url causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10287">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10286 – A vulnerability was found in CodeAstro Payroll System 1.0. This affects an unkno...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10286</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10286</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10286</strong></p>
  <p>A vulnerability was found in CodeAstro Payroll System 1.0. This affects an unknown part of the file /home_employee.php. The manipulation of the argument emp_id results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10286">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10285 – A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-bet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10285</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10285</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10285</strong></p>
  <p>A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordUpdated of the file app/Helpers/KanbanScrumHelper.php of the component Ticket Handler. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10285">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10284 – A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10284</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10284</guid>
    <pubDate>Mon, 01 Jun 2026 21:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10284</strong></p>
  <p>A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the function editComment/doDeleteComment of the file app/Filament/Resources/TicketResource/Pages/ViewTicket.php of the component Livewire Handler. Executing a manipulation can lead to improper authorization. The attack can be executed remotely. The project was informed of the problem early…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10284">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10282 – A security vulnerability has been detected in Bottelet DaybydayCRM up to 2.2.1. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10282</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10282</guid>
    <pubDate>Mon, 01 Jun 2026 19:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10282</strong></p>
  <p>A security vulnerability has been detected in Bottelet DaybydayCRM up to 2.2.1. This impacts the function view of the file app/Http/Controllers/DocumentsController.php. Such manipulation leads to improper authorization. The attack may be launched remotely. It is best practice to apply a patch to resolve this issue.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10282">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45701 – Sulu is an open-source PHP content management system based on the Symfony framew...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45701</guid>
    <pubDate>Mon, 01 Jun 2026 17:17:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45701</strong></p>
  <p>Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.23 and 3.0.6, the password reset tokenand API key generation uses a weak cryptographical hash algorithm. This issue has been patched in versions 2.6.23 and 3.0.6.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-327</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10273 – A vulnerability was found in php-censor up to 2.1.6. This affects an unknown fun...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10273</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10273</guid>
    <pubDate>Mon, 01 Jun 2026 17:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10273</strong></p>
  <p>A vulnerability was found in php-censor up to 2.1.6. This affects an unknown function of the file src/Model/Build/GitBuild.php of the component Webhook Endpoint. Performing a manipulation of the argument commitId results in os command injection. The attack can be initiated remotely. The exploit has been made public and could be used. The patch is named cd68d102601320bd319d590b75f7652e66f0685f. It…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10273">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10272 – A vulnerability has been found in a4m4 Student-Management-System up to f0c5f6842...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10272</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10272</guid>
    <pubDate>Mon, 01 Jun 2026 17:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10272</strong></p>
  <p>A vulnerability has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The impacted element is an unknown function of the file admin/deleteform.php. Such manipulation of the argument sid leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product takes the approa…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10272">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10265 – A vulnerability was identified in itsourcecode Content Management System 1.0. Af...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10265</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10265</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10265</strong></p>
  <p>A vulnerability was identified in itsourcecode Content Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/edit_topic.php. Such manipulation of the argument topic_id leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10265">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10263 – A vulnerability was found in SourceCodester Computer Repair Shop Management Syst...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10263</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10263</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10263</strong></p>
  <p>A vulnerability was found in SourceCodester Computer Repair Shop Management System up to 1.0. Affected is an unknown function of the file /admin/products/manage_product.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10263">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10262 – A vulnerability has been found in code-projects Real State Services 1.0. This im...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10262</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10262</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10262</strong></p>
  <p>A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10262">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10261 – A flaw has been found in CodeAstro Online Job Portal 1.0. This affects an unknow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10261</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10261</strong></p>
  <p>A flaw has been found in CodeAstro Online Job Portal 1.0. This affects an unknown function of the file /users/application_status.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10260 – A vulnerability was detected in CodeAstro Online Job Portal 1.0. The impacted el...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10260</guid>
    <pubDate>Mon, 01 Jun 2026 15:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10260</strong></p>
  <p>A vulnerability was detected in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /admin/jobs-admins/delete-jobs.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10258 – A weakness has been identified in itsourcecode Content Management System 1.0. Im...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10258</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10258</guid>
    <pubDate>Mon, 01 Jun 2026 13:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10258</strong></p>
  <p>A weakness has been identified in itsourcecode Content Management System 1.0. Impacted is an unknown function of the file /admin/add_sub_topic.php. This manipulation of the argument topic_id causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10258">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10257 – A security flaw has been discovered in itsourcecode Content Management System 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10257</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10257</guid>
    <pubDate>Mon, 01 Jun 2026 13:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10257</strong></p>
  <p>A security flaw has been discovered in itsourcecode Content Management System 1.0. This issue affects some unknown processing of the file /admin/update_ss_img.php. The manipulation of the argument topic_id results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10257">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10256 – A vulnerability was identified in itsourcecode Content Management System 1.0. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10256</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10256</guid>
    <pubDate>Mon, 01 Jun 2026 13:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10256</strong></p>
  <p>A vulnerability was identified in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /save_comment.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10256">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10255 – A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory Sy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10255</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10255</guid>
    <pubDate>Mon, 01 Jun 2026 13:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10255</strong></p>
  <p>A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function sell_statement of the file application/controllers/ShowForm.php. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10255">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10253 – A vulnerability was detected in itsourcecode Online House Rental System 1.0. Thi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10253</guid>
    <pubDate>Mon, 01 Jun 2026 13:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10253</strong></p>
  <p>A vulnerability was detected in itsourcecode Online House Rental System 1.0. This impacts an unknown function of the file /manage_payment.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10252 – A security vulnerability has been detected in itsourcecode Online House Rental S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10252</guid>
    <pubDate>Mon, 01 Jun 2026 13:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10252</strong></p>
  <p>A security vulnerability has been detected in itsourcecode Online House Rental System 1.0. This affects an unknown function of the file /manage_tenant.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10251 – A weakness has been identified in itsourcecode Online House Rental System 1.0. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10251</guid>
    <pubDate>Mon, 01 Jun 2026 13:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10251</strong></p>
  <p>A weakness has been identified in itsourcecode Online House Rental System 1.0. The impacted element is an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10250 – A security flaw has been discovered in itsourcecode Online Blood Bank Management...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10250</guid>
    <pubDate>Mon, 01 Jun 2026 11:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10250</strong></p>
  <p>A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an unknown function of the file /admin/campsdetails.php. Performing a manipulation of the argument hospital results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10249 – A vulnerability was identified in itsourcecode Online Blood Bank Management Syst...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10249</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10249</guid>
    <pubDate>Mon, 01 Jun 2026 11:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10249</strong></p>
  <p>A vulnerability was identified in itsourcecode Online Blood Bank Management System 1.0. Impacted is an unknown function of the file /admin/viewrequest.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10249">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-40548 – SOPlanning does not verify uploaded file extension. An authenticated attacker wi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40548</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40548</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-40548</strong></p>
  <p>SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archive containing a legitimate user.csv file alongside a malicious file, which is extracted on the server. When combined with CVE-2026-40547 (Path Traversal), the malicious file (e.g., a PHP script) can be placed in a web-accessible location and executed…</p>
  <p><strong>CVSS:</strong> 6.4 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40548">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10242 – A weakness has been identified in itsourcecode Content Management System 1.0. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10242</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10242</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10242</strong></p>
  <p>A weakness has been identified in itsourcecode Content Management System 1.0. This impacts an unknown function of the file /instructions.php. This manipulation of the argument topic_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10242">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10236 – A vulnerability has been found in SourceCodester Water Billing Management System...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10236</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10236</guid>
    <pubDate>Mon, 01 Jun 2026 09:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10236</strong></p>
  <p>A vulnerability has been found in SourceCodester Water Billing Management System 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=save of the component User Management Endpoint. Such manipulation leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10236">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10235 – A flaw has been found in CodeAstro Ingredients Stock Management System 1.0. This...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10235</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10235</guid>
    <pubDate>Mon, 01 Jun 2026 08:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10235</strong></p>
  <p>A flaw has been found in CodeAstro Ingredients Stock Management System 1.0. This vulnerability affects unknown code of the file /Ingredients-Stock/stock_manager.php. This manipulation of the argument txt_search_category causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10235">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10228 – A vulnerability was found in raisulislamg4 student_management_system_by_php up t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10228</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10228</guid>
    <pubDate>Mon, 01 Jun 2026 08:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10228</strong></p>
  <p>A vulnerability was found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. The impacted element is an unknown function of the file admission_form_check.php. The manipulation of the argument Message results in cross site scripting. The attack can be executed remotely. The exploit has been made public and could be used. This product implements a roll…</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10228">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10227 – A vulnerability has been found in raisulislamg4 student_management_system_by_php...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10227</guid>
    <pubDate>Mon, 01 Jun 2026 06:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10227</strong></p>
  <p>A vulnerability has been found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. The affected element is an unknown function of the file add_user_check.php of the component User Creation Handler. The manipulation of the argument role leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public a…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10226 – A flaw has been found in raisulislamg4 student_management_system_by_php up to 31...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10226</guid>
    <pubDate>Mon, 01 Jun 2026 06:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10226</strong></p>
  <p>A flaw has been found in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. Impacted is an unknown function of the file delete.php. Executing a manipulation of the argument user_id/course_id/teacher_id/student_id/application_id can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. This product op…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10225 – A vulnerability was detected in raisulislamg4 student_management_system_by_php u...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10225</guid>
    <pubDate>Mon, 01 Jun 2026 06:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10225</strong></p>
  <p>A vulnerability was detected in raisulislamg4 student_management_system_by_php up to 310d950e09013d5133c6b9210aff9444382d16d1. This issue affects some unknown processing of the file login_check.php of the component Login. Performing a manipulation of the argument Username results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. This product uses a…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10225">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10215 – A security vulnerability has been detected in Dolibarr ERP CRM up to 23.0.1. Imp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10215</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10215</guid>
    <pubDate>Mon, 01 Jun 2026 03:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10215</strong></p>
  <p>A security vulnerability has been detected in Dolibarr ERP CRM up to 23.0.1. Impacted is the function checkUserAccessToObject of the file htdocs/holiday/class/api_holidays.class.php of the component Leave Request REST API. The manipulation leads to improper authorization. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 23.0.2 is…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-266</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10215">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10209 – A vulnerability has been found in code-projects Online Hospital Management Syste...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10209</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10209</guid>
    <pubDate>Mon, 01 Jun 2026 02:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10209</strong></p>
  <p>A vulnerability has been found in code-projects Online Hospital Management System 1.0. Affected is an unknown function of the file appointmentdetail.php of the component Appointment Handler. The manipulation of the argument editid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10209">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10208 – A flaw has been found in code-projects Online Hospital Management System 1.php. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10208</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10208</guid>
    <pubDate>Mon, 01 Jun 2026 02:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10208</strong></p>
  <p>A flaw has been found in code-projects Online Hospital Management System 1.php. This impacts the function login_user of the file login_1.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10208">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10186 – A security vulnerability has been detected in code-projects Online Hospital Mana...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10186</guid>
    <pubDate>Sun, 31 May 2026 14:16:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10186</strong></p>
  <p>A security vulnerability has been detected in code-projects Online Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patient.php. Such manipulation of the argument editid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10185 – A weakness has been identified in SourceCodester Hospitals Patient Records Manag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10185</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10185</guid>
    <pubDate>Sun, 31 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10185</strong></p>
  <p>A weakness has been identified in SourceCodester Hospitals Patient Records Management System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10185">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10184 – A security flaw has been discovered in SourceCodester Hospitals Patient Records ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10184</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10184</guid>
    <pubDate>Sun, 31 May 2026 14:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10184</strong></p>
  <p>A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This impacts an unknown function of the file /classes/Users.php?f=delete. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10184">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-49489 – OpenCATS through 0.9.7.4 contains a sql injection vulnerability in the sortDirec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-49489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-49489</guid>
    <pubDate>Sun, 31 May 2026 13:16:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-49489</strong></p>
  <p>OpenCATS through 0.9.7.4 contains a sql injection vulnerability in the sortDirection parameter of the DataGrid component that allows authenticated users to extract database contents. Attackers can inject malicious SQL via the sortDirection parameter in ajax/getDataGridPager.php to perform time-based blind injection attacks and read sensitive data.</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10178 – A vulnerability was detected in code-projects Online Music Site 1.0. This vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10178</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10178</guid>
    <pubDate>Sun, 31 May 2026 11:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10178</strong></p>
  <p>A vulnerability was detected in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /Administrator/PHP/AdminEditAlbum.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10178">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10172 – A security flaw has been discovered in Bdtask Multi-Store Inventory Management S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10172</guid>
    <pubDate>Sun, 31 May 2026 08:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10172</strong></p>
  <p>A security flaw has been discovered in Bdtask Multi-Store Inventory Management System 1.0. The affected element is the function Upload of the file application/modules/dashboard/controllers/Module.php of the component Component Module. The manipulation of the argument module results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10171 – A vulnerability has been found in code-projects Online Music Site 1.0. This affe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10171</guid>
    <pubDate>Sun, 31 May 2026 07:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10171</strong></p>
  <p>A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminUpdateAlbum.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10170 – A flaw has been found in code-projects Visitor Management System 1.0. Affected b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10170</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10170</guid>
    <pubDate>Sun, 31 May 2026 07:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10170</strong></p>
  <p>A flaw has been found in code-projects Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /vms/php/phone_0.php. This manipulation of the argument phone causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10170">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-10169 – A vulnerability was detected in OUSL-GROUP-BrinaryBrains School Student Manageme...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10169</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10169</guid>
    <pubDate>Sun, 31 May 2026 05:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-10169</strong></p>
  <p>A vulnerability was detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. Affected by this vulnerability is the function ajax_forgot_password of the file application/controllers/Login.php of the component Forgot Password Endpoint. The manipulation of the argument email results in weak password recovery. The attack can be launched rem…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10169">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10168 – A security vulnerability has been detected in OUSL-GROUP-BrinaryBrains School St...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10168</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10168</guid>
    <pubDate>Sun, 31 May 2026 05:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10168</strong></p>
  <p>A security vulnerability has been detected in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. Affected is the function marks of the file application/controllers/Parents.php. The manipulation of the argument param1 leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit has been disclosed publicl…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-99</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10168">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-10167 – A weakness has been identified in OUSL-GROUP-BrinaryBrains School Student Manage...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10167</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10167</guid>
    <pubDate>Sun, 31 May 2026 05:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-10167</strong></p>
  <p>A weakness has been identified in OUSL-GROUP-BrinaryBrains School Student Management System up to 1e70e5ad1125b86dca4ee086eb6bb121f17708b6. This impacts the function sign_auth_cookie of the file application/controllers/Login.php of the component MY_Controller. Executing a manipulation of the argument role can lead to improper authentication. It is possible to launch the attack remotely. The explo…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10167">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10155 – A vulnerability was found in Bdtask Multi-Store Inventory Management System 1.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10155</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10155</guid>
    <pubDate>Sun, 31 May 2026 00:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10155</strong></p>
  <p>A vulnerability was found in Bdtask Multi-Store Inventory Management System 1.0. The impacted element is the function accounts_report_search of the file application/modules/accounts/controllers/Accounts.php of the component Accounts Report Handler. Performing a manipulation of the argument dtpToDate results in sql injection. The attack is possible to be carried out remotely. The exploit has been…</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10155">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-10154 – A vulnerability has been found in Dolibarr ERP CRM 23.0.0/23.0.1/23.0.2. The aff...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10154</guid>
    <pubDate>Sun, 31 May 2026 00:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10154</strong></p>
  <p>A vulnerability has been found in Dolibarr ERP CRM 23.0.0/23.0.1/23.0.2. The affected element is an unknown function of the file htdocs/user/messaging.php. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. Upgrading to version 23.0.3 is sufficient to fix this issue. The name of the patch is 119b3606c7a701747a57a1f18b1a9e7666f678e2. It is sugg…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25425 – Yot CMS 3.3.1 contains an SQL injection vulnerability that allows unauthenticate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25425</guid>
    <pubDate>Sat, 30 May 2026 16:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25425</strong></p>
  <p>Yot CMS 3.3.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the aid and cid parameters. Attackers can send GET requests to index.php with crafted SQL payloads in the aid or cid parameters to extract database information including table and column names.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25424 – Gate Pass Management System 2.1 contains an SQL injection vulnerability that all...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25424</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25424</guid>
    <pubDate>Sat, 30 May 2026 16:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25424</strong></p>
  <p>Gate Pass Management System 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the login and password parameters. Attackers can submit crafted POST requests to login-exec.php with SQL injection payloads in form parameters to authenticate without valid credentials and gain access to the application.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25424">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25422 – MOGG web simulator Script contains an SQL injection vulnerability that allows un...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25422</guid>
    <pubDate>Sat, 30 May 2026 16:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25422</strong></p>
  <p>MOGG web simulator Script contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through the id parameter. Attackers can send GET requests to play.php with crafted SQL payloads in the id parameter to extract sensitive database information including usernames and other data.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-25421 – Open STA Manager 2.3 contains a path traversal vulnerability that allows authent...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25421</guid>
    <pubDate>Sat, 30 May 2026 16:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-25421</strong></p>
  <p>Open STA Manager 2.3 contains a path traversal vulnerability that allows authenticated users to download arbitrary files by manipulating the file parameter. Attackers can send GET requests to modules/backup/actions.php with op=getfile and traverse directories using ../ sequences to access sensitive system files.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25420 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25420</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25420</guid>
    <pubDate>Sat, 30 May 2026 16:17:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25420</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to watch.php with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25420">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25419 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25419</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25419</guid>
    <pubDate>Sat, 30 May 2026 16:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25419</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the genre parameter. Attackers can send GET requests to genre.php with crafted SQL payloads in the genre parameter to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25419">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25418 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25418</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25418</guid>
    <pubDate>Sat, 30 May 2026 16:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25418</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the year parameter. Attackers can send GET requests to year.php with crafted SQL payloads in the year parameter to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25418">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25417 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25417</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25417</guid>
    <pubDate>Sat, 30 May 2026 16:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25417</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the quality parameter. Attackers can send GET requests to quality.php with crafted SQL payloads in the quality parameter to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25417">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25416 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25416</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25416</guid>
    <pubDate>Sat, 30 May 2026 16:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25416</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the country parameter. Attackers can send GET requests to country.php with crafted SQL payloads in the country parameter to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25416">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25415 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25415</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25415</guid>
    <pubDate>Sat, 30 May 2026 16:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25415</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the director parameter. Attackers can send GET requests to director.php with crafted SQL payloads in the director parameter to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25415">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25414 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25414</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25414</guid>
    <pubDate>Sat, 30 May 2026 16:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25414</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the actor parameter. Attackers can send GET requests to actor.php with crafted SQL payloads in the actor parameter to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25414">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25413 – AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25413</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25413</guid>
    <pubDate>Sat, 30 May 2026 16:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25413</strong></p>
  <p>AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'q' parameter. Attackers can send GET requests to search.php with crafted SQL payloads to extract sensitive database information including usernames, database names, and version details.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25413">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
