Campcodes
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Campcodes product.
RSS Feeds for Campcodes security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Campcodes products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Campcodes Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 4 vulnerabilities in Campcodes with an average score of 4.9 out of ten. Last year, in 2025 Campcodes had 270 security vulnerabilities published. Right now, Campcodes is on track to have less security vulnerabilities in 2026 than it did last year. Last year, the average CVE base score was greater by 3.35
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 4 | 4.90 |
| 2025 | 270 | 8.25 |
| 2024 | 223 | 6.77 |
| 2023 | 41 | 7.70 |
It may take a day or so for new Campcodes vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Campcodes Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-3984 | Mar 12, 2026 |
CVE-2026-3984A weakness has been identified in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This vulnerability affects unknown code of the file save_up_athlete.php. This manipulation of the argument a_name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-3983 | Mar 12, 2026 |
CVE-2026-3983A security flaw has been discovered in Campcodes Division Regional Athletic Meet Game Result Matrix System 2.1. This affects an unknown part of the file save-games.php. The manipulation of the argument game_name results in cross site scripting. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-0597 | Jan 05, 2026 |
CVE-2026-0597A flaw has been found in Campcodes Supplier Management System 1.0. Affected by this issue is some unknown functionality of the file /retailer/edit_profile.php. This manipulation of the argument txtRetailerAddress causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. |
|
| CVE-2025-15404 | Jan 01, 2026 |
CVE-2025-15404A security vulnerability has been detected in campcodes School File Management System 1.0. The affected element is an unknown function of the file /save_file.php. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2025-15214 | Dec 30, 2025 |
A vulnerability was found in Campcodes Park Ticketing System 1.0A vulnerability was found in Campcodes Park Ticketing System 1.0. The impacted element is the function save_pricing of the file admin_class.php. The manipulation of the argument name/ride results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used. |
|
| CVE-2025-15207 | Dec 29, 2025 |
A vulnerability has been found in Campcodes Supplier Management System 1.0A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/view_products.php. The manipulation of the argument chkId[] leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-15206 | Dec 29, 2025 |
A flaw has been found in Campcodes Supplier Management System 1.0A flaw has been found in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /admin/add_area.php. Executing a manipulation of the argument txtAreaCode can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. |
|
| CVE-2025-15188 | Dec 29, 2025 |
A vulnerability was determined in Campcodes Complete Online Beauty Parlor Management System 1.0A vulnerability was determined in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affects unknown code of the file /admin/search-invoices.php. Executing a manipulation of the argument searchdata can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2025-14991 | Dec 21, 2025 |
Campcodes Parlor Mgt Sys 1.0 XSS via fromdate bwdates-reports-details.phpA weakness has been identified in Campcodes Complete Online Beauty Parlor Management System 1.0. The affected element is an unknown function of the file /admin/bwdates-reports-details.php. Executing a manipulation of the argument fromdate can lead to cross site scripting. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2025-14990 | Dec 21, 2025 |
SQLi in Campcodes Parlor Mgmt 1.0 /admin/view-appointment.php via viewidA security flaw has been discovered in Campcodes Complete Online Beauty Parlor Management System 1.0. Impacted is an unknown function of the file /admin/view-appointment.php. Performing a manipulation of the argument viewid results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2025-14989 | Dec 20, 2025 |
Campcodes Beauty PM 1.0 SQLi via /admin/search-invoices.phpA vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This issue affects some unknown processing of the file /admin/search-invoices.php. Such manipulation leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. |
|
| CVE-2025-14952 | Dec 19, 2025 |
SQLi in Campcodes Supplier Mgmt Sys 1.0 via txtCategoryName in add_category.phpA vulnerability was detected in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_category.php. Performing a manipulation of the argument txtCategoryName results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. |
|
| CVE-2025-14889 | Dec 18, 2025 |
Improper Authorization via ID Manipulation in Campcodes A/VMS 1.0A security flaw has been discovered in Campcodes Advanced Voting Management System 1.0. The impacted element is an unknown function of the file /admin/voters_edit.php of the component Password Handler. Performing a manipulation of the argument ID results in improper authorization. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2025-14877 | Dec 18, 2025 |
Campcodes Supplier Mgmt Sys 1.0: SQLi via /admin/add_retailer.php (cmbAreaCode)A vulnerability was identified in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_retailer.php. The manipulation of the argument cmbAreaCode leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. |
|
| CVE-2025-14668 | Dec 14, 2025 |
CVE-2025-14668: SQLi in campcodes A.O.E.S 1.0 via /query/loginExe.phpA vulnerability was detected in campcodes Advanced Online Examination System 1.0. This affects an unknown function of the file /query/loginExe.php. Performing a manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. |
|
| CVE-2025-14664 | Dec 14, 2025 |
SQLi in Campcodes Supplier Management System 1.0 /admin/view_unit.phpA vulnerability was identified in Campcodes Supplier Management System 1.0. This issue affects some unknown processing of the file /admin/view_unit.php. The manipulation of the argument chkId[] leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. |
|
| CVE-2025-14583 | Dec 12, 2025 |
Unrestricted file upload in campcodes Student Sys 1.0 via /admin/register.phpA flaw has been found in campcodes Online Student Enrollment System 1.0. This impacts an unknown function of the file /admin/register.php. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used. |
|
| CVE-2025-14582 | Dec 12, 2025 |
Unrestricted File Upload in CampCodes OSE 1.0 (admin/user-profile)A vulnerability was detected in campcodes Online Student Enrollment System 1.0. This affects an unknown function of the file /admin/index.php?page=user-profile. Performing a manipulation of the argument userphoto results in unrestricted upload. The attack can be initiated remotely. The exploit is now public and may be used. |
|
| CVE-2025-14529 | Dec 11, 2025 |
Campcodes Retro Store 1.0 SQLi /admin/admin_running.php pidA flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The affected element is an unknown function of the file /admin/admin_running.php. This manipulation of the argument pid causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. |
|
| CVE-2025-14515 | Dec 11, 2025 |
SQLi in Campcodes Supplier Mgmt Sys 1.0 via /admin/add_unit.phpA vulnerability has been found in Campcodes Supplier Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add_unit.php. Such manipulation of the argument txtunitDetails leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-14514 | Dec 11, 2025 |
CVE-2025-14514 Remote SQLi Campcodes Supplier Mgmt 1.0 /admin/add_distributor.phpA flaw has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/add_distributor.php. This manipulation of the argument txtDistributorAddress causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. |
|
| CVE-2025-14219 | Dec 08, 2025 |
Unrestricted Upload in Campcodes Basketball Shoes Store v1.0 (admin_running.php)A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_running.php. Executing a manipulation of the argument product_image can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2025-14209 | Dec 08, 2025 |
SQLi via /update_query.php in Campcodes School File Mgt Sys 1.0A weakness has been identified in Campcodes School File Management System 1.0. This impacts an unknown function of the file /update_query.php. This manipulation of the argument stud_id causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2025-13557 | Nov 23, 2025 |
Campcodes Online Polling System 1.0 SQL Injection via /registeracc.phpA vulnerability has been found in Campcodes Online Polling System 1.0. Affected by this issue is some unknown functionality of the file /registeracc.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-13556 | Nov 23, 2025 |
Campcodes OPS 1.0 - SQLi in admin/checklogin.phpA flaw has been found in Campcodes Online Polling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/checklogin.php. Executing a manipulation of the argument myusername can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. |
|
| CVE-2025-13555 | Nov 23, 2025 |
SQLi via stud_no in Campcodes SFS 1.0 Login (index.php)A vulnerability was detected in Campcodes School File Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument stud_no results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used. |
|
| CVE-2025-13554 | Nov 23, 2025 |
Campcodes Supplier Management System 1.0 SQLi via txtUsername in /index.php RmtA security vulnerability has been detected in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /index.php of the component Login. Such manipulation of the argument txtUsername leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2025-13484 | Nov 20, 2025 |
Campcodes Beauty Parlor Mgmt Sys 1.0 XSS via Name in admin/cust-list.phpA vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affects unknown code of the file /admin/customer-list.php. The manipulation of the argument Name leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used. |
|
| CVE-2025-13424 | Nov 20, 2025 |
CVE-2025-13424: Campcodes 1.0 SQLi in /admin/add_product.php via txtProductNameA vulnerability has been found in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_product.php. The manipulation of the argument txtProductName leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-13423 | Nov 19, 2025 |
Unrestricted upload via product_image in Campcodes RetroBS 1.0 admin_product.phpA flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/admin_product.php. Executing a manipulation of the argument product_image can lead to unrestricted upload. The attack may be launched remotely. The exploit has been published and may be used. |
|
| CVE-2025-13412 | Nov 19, 2025 |
XSS in Campcodes Retro Shoes Store 1.0 via /admin/admin_running.phpA vulnerability was determined in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_running.php. Executing a manipulation of the argument product_name can lead to cross site scripting. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2025-13411 | Nov 19, 2025 |
Campcodes 1.0: Unrestricted File Upload in admin_football.phpA vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Performing a manipulation of the argument product_image results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used. |
|
| CVE-2025-13410 | Nov 19, 2025 |
SQLi via tid in /admin/receipt.php in Campcodes Retro Basketball Shoes Online Store 1.0A vulnerability has been found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected is an unknown function of the file /admin/receipt.php. Such manipulation of the argument tid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-13291 | Nov 17, 2025 |
Campcodes Supplier Mgt Sys 1.0: Remote SQLi via /manufacturer/confirm_order.phpA vulnerability was found in Campcodes Supplier Management System 1.0. This affects an unknown part of the file /manufacturer/confirm_order.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. |
|
| CVE-2025-13274 | Nov 17, 2025 |
SQL Injection via /ajax.php in Campcodes School Fees System 1.0A weakness has been identified in Campcodes School Fees Payment Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=delete_fees. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2025-13273 | Nov 17, 2025 |
SQLi in Campcodes School Fees PM 1.0 via /ajax.php?action=delete_paymentA security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=delete_payment. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2025-13272 | Nov 17, 2025 |
Campcodes School Fees PM 1.0 SQLi via /manage_course.php ID RemoteA vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Affected is an unknown function of the file /manage_course.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. |
|
| CVE-2025-13271 | Nov 17, 2025 |
CVE-2025-13271: Remote SQLi in Campcodes School Fees PM 1.0 (login)A vulnerability was determined in Campcodes School Fees Payment Management System 1.0. This impacts an unknown function of the file /ajax.php?action=login. This manipulation of the argument Username causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2025-13270 | Nov 17, 2025 |
Campcodes SFPMS 1.0 SQLi via /ajax.php?action=save_course IDA vulnerability was found in Campcodes School Fees Payment Management System 1.0. This affects an unknown function of the file /ajax.php?action=save_course. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. |
|
| CVE-2025-13269 | Nov 17, 2025 |
SQL Injection in Campcodes School Fees PM v1.0 via /ajax.php?action=save_paymentA vulnerability has been found in Campcodes School Fees Payment Management System 1.0. The impacted element is an unknown function of the file /ajax.php?action=save_payment. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-13260 | Nov 17, 2025 |
SQLi in Campcodes Supplier Management System 1.0 edit_product.php via cmbProductUnitA vulnerability has been found in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /manufacturer/edit_product.php. Such manipulation of the argument cmbProductUnit leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-13259 | Nov 17, 2025 |
SQL Injection in Campcodes Supplier Management System 1.0 /edit_unit.phpA flaw has been found in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /manufacturer/edit_unit.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. |
|
| CVE-2025-13057 | Nov 12, 2025 |
Campcodes Fees Mgt 1.0: Remote SQLI via ID in /ajax.php?action=save_studentA vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_student. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. |
|
| CVE-2025-12873 | Nov 07, 2025 |
Remote SQLi in Campcodes School File Management 1.0 /admin/update_userA security flaw has been discovered in Campcodes School File Management 1.0. This affects an unknown part of the file /admin/update_user.php. Performing manipulation of the argument user_id results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited. |
|
| CVE-2025-12612 | Nov 03, 2025 |
Remote SQLi via /ajax.php in Campcodes School Fees Payment Management System 1.0A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_course. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2025-12339 | Oct 28, 2025 |
SQLi in Campcodes Retro Basketball Shoes Store 1.0 /admin/admin_football.phpA security vulnerability has been detected in Campcodes Retro Basketball Shoes Online Store 1.0. This issue affects some unknown processing of the file /admin/admin_football.php. The manipulation of the argument pid leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. |
|
| CVE-2025-12338 | Oct 28, 2025 |
SQLi in Campcodes RBS Online Store 1.0 /admin/admin_product.ph pidA weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. This vulnerability affects unknown code of the file /admin/admin_product.ph. Executing a manipulation of the argument pid can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2025-12337 | Oct 28, 2025 |
Campcodes Retro Basketball Shoes 1.0 SQLi via admin_feature.php pidA security flaw has been discovered in Campcodes Retro Basketball Shoes Online Store 1.0. This affects an unknown part of the file /admin/admin_feature.php. Performing a manipulation of the argument pid results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2025-12336 | Oct 28, 2025 |
SQLi in /admin/admin_index.php of Campcodes RBS Online Store 1.0A vulnerability was identified in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_index.php. Such manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. |
|
| CVE-2025-11664 | Oct 13, 2025 |
CVE-2025-11664: SQLi in Campcodes Beauty PMS 1.0 /admin/search-appointment.phpA security vulnerability has been detected in Campcodes Online Beauty Parlor Management System 1.0. The impacted element is an unknown function of the file /admin/search-appointment.php. Such manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. |
|