Sales And Inventory System Campcodes Sales And Inventory System

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Campcodes Sales And Inventory System.

By the Year

In 2026 there have been 0 vulnerabilities in Campcodes Sales And Inventory System. Last year, in 2025 Sales And Inventory System had 37 security vulnerabilities published. Right now, Sales And Inventory System is on track to have less security vulnerabilities in 2026 than it did last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 37 9.77

It may take a day or so for new Sales And Inventory System vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Campcodes Sales And Inventory System Security Vulnerabilities

Campcodes Sales & Inventory Sys 1.0 SQLi in settings_update.php (ID)
CVE-2025-7933 9.8 - Critical - July 21, 2025

A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/settings_update.php of the component Setting Handler. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Unrestricted File Upload in Campcodes Sales & Inv System 1.0 (image.php)
CVE-2025-7538 9.8 - Critical - July 13, 2025

A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/product_update.php. The manipulation of the argument image leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

Authorization

CVE-2025-7537: SQLi in Campcodes Sales & Inventory 1.0 product_update.php
CVE-2025-7537 9.8 - Critical - July 13, 2025

A vulnerability classified as critical has been found in Campcodes Sales and Inventory System 1.0. This affects an unknown part of the file /pages/product_update.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

SQLi via sid in /pages/receipt_credit.php of Campcodes Sales & Inv System v1.0
CVE-2025-7536 9.8 - Critical - July 13, 2025

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /pages/receipt_credit.php. The manipulation of the argument sid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Campcodes SIS 1.0 – Critical SQLi via /pages/reprint_cash.php sid
CVE-2025-7535 9.8 - Critical - July 13, 2025

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /pages/reprint_cash.php. The manipulation of the argument sid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Campcodes Sales & Inventory System 1.0 - Unrestricted file upload via image
CVE-2025-7470 9.8 - Critical - July 12, 2025

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is an unknown function of the file /pages/product_add.php. The manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Unrestricted File Upload

Campcodes SIS 1.0: Remote SQLi via prod_name in product_add.php
CVE-2025-7469 9.8 - Critical - July 12, 2025

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. This issue affects some unknown processing of the file /pages/product_add.php. The manipulation of the argument prod_name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

SQLi in Campcodes Sales & Inventory System 1.0 CustomerAccount.php
CVE-2025-7183 9.8 - Critical - July 08, 2025

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/customer_account.php. The manipulation of the argument Customer leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

SQLi via cid in Campcodes Sales & Inventory System 1.0 /pages/payment_add
CVE-2025-6935 9.8 - Critical - July 01, 2025

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/payment_add.php. The manipulation of the argument cid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

SQLi in Campcodes S&I System 1.0 via cat_add.php (Category arg)
CVE-2025-6313 9.8 - Critical - June 20, 2025

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. This issue affects some unknown processing of the file /pages/cat_add.php. The manipulation of the argument Category leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Campcodes Sales & Inventory Syst 1.0 SQL Inject via cat_update.php ID
CVE-2025-6314 9.8 - Critical - June 20, 2025

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is an unknown function of the file /pages/cat_update.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Campcodes Sales & Inventory Sys 1.0 SQLi via account_add.php id/amount
CVE-2025-6311 9.8 - Critical - June 20, 2025

A vulnerability, which was classified as critical, was found in Campcodes Sales and Inventory System 1.0. This affects an unknown part of the file /pages/account_add.php. The manipulation of the argument id/amount leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

CVE-2025-6312: SQLi in Campcodes S&I System 1.0 (cash_transaction.php)
CVE-2025-6312 9.8 - Critical - June 20, 2025

A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerability affects unknown code of the file /pages/cash_transaction.php. The manipulation of the argument cid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Campcodes 1.0 SQLi in transaction_update.php via ID param
CVE-2025-4899 9.8 - Critical - May 18, 2025

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /pages/transaction_update.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Campcodes Sales and Inventory System 1.0 - SQLi via cid in payment.php
CVE-2025-4900 9.8 - Critical - May 18, 2025

A vulnerability classified as critical has been found in Campcodes Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/payment.php. The manipulation of the argument cid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

SQLi via /pages/product_update.php serial param in itsourcecode Sales/Inv. 1.0
CVE-2025-4886 9.8 - Critical - May 18, 2025

A vulnerability classified as critical was found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/product_update.php. The manipulation of the argument serial leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

SQL Injection

CVE-2025-4885 SQLi in itsourcecode Sales & Inventory Syst 1.0 product_add
CVE-2025-4885 9.8 - Critical - May 18, 2025

A vulnerability classified as critical has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/product_add.php. The manipulation of the argument serial leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

SQL Injection

Campcodes Sales & Inventory 1.0: SQLi via supplier_add.php Name Arg
CVE-2025-4814 9.8 - Critical - May 17, 2025

A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pages/supplier_add.php. The manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Campcodes Sales & Inventory System 1.0 SQLi via supplier_update.php
CVE-2025-4815 9.8 - Critical - May 17, 2025

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/supplier_update.php. The manipulation of the argument Name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Campcodes Sales and Inventory System 1.0 SQLi in purchase_delete.php via pr_id
CVE-2025-4746 9.8 - Critical - May 16, 2025

A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerability affects unknown code of the file /pages/purchase_delete.php. The manipulation of the argument pr_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

CVE-2025-4741: Critical SQLi via ID in Campcodes Sale 1.0 purchase_add.php
CVE-2025-4741 9.8 - Critical - May 16, 2025

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /pages/purchase_add.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Campcodes Sales&Inv Sys 1.0 Unrestricted Upload via Picture (Critical)
CVE-2025-4735 8.8 - High - May 16, 2025

A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pages/product.php. The manipulation of the argument Picture leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Unrestricted File Upload

Campcodes Sales & Inventory System 1.0 – Remote SQLi via ci_update.php
CVE-2025-4734 9.8 - Critical - May 16, 2025

A vulnerability, which was classified as critical, was found in Campcodes Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/ci_update.php. The manipulation of the argument id/name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Campcodes Sales & Inventory 1.0 Remote SQLi via cid in cash_transaction.php
CVE-2025-4719 9.8 - Critical - May 15, 2025

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/cash_transaction.php. The manipulation of the argument cid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Campcodes Sales & Inventory 1.0: Remote SQLi via customer_add.php Arg
CVE-2025-4718 9.8 - Critical - May 15, 2025

A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pages/customer_add.php. The manipulation of the argument last leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

SQL Injection

SQLi in Campcodes Sales & Inventory System 1.0 via /pages/view_application.php
CVE-2025-4715 9.8 - Critical - May 15, 2025

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /pages/view_application.php. The manipulation of the argument cid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Critical SQLi in Campcodes Sales System 1.0 via prod_name
CVE-2025-4716 9.8 - Critical - May 15, 2025

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /pages/credit_transaction_add.php. The manipulation of the argument prod_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Campcodes Sales & Inventory 1.0: Critical Remote SQLi in account_summary.php
CVE-2025-4712 9.8 - Critical - May 15, 2025

A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerability affects unknown code of the file /pages/account_summary.php. The manipulation of the argument cid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Campcodes Sales & Inventory System 1.0 SQLi via reprint.php sid parameter
CVE-2025-4714 9.8 - Critical - May 15, 2025

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as critical. Affected is an unknown function of the file /pages/reprint.php. The manipulation of the argument sid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

SQLi in Campcodes Sales & Inventory System 1.0 via sid in print.php
CVE-2025-4713 9.8 - Critical - May 15, 2025

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. This issue affects some unknown processing of the file /pages/print.php. The manipulation of the argument sid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Campcodes Sales & Inventory Sys 1.0 SQLi in /pages/transaction.php (cid)
CVE-2025-4710 9.8 - Critical - May 15, 2025

A vulnerability, which was classified as critical, has been found in Campcodes Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/transaction.php. The manipulation of the argument cid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

SQLi via ID in Campcodes Sales & Inventory Sys 1.0 transaction_del.php
CVE-2025-4709 9.8 - Critical - May 15, 2025

A vulnerability classified as critical was found in Campcodes Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/transaction_del.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Remote SQLi via prod_name in Campcodes Sales & Inventory System 1.0
CVE-2025-4711 9.8 - Critical - May 15, 2025

A vulnerability, which was classified as critical, was found in Campcodes Sales and Inventory System 1.0. This affects an unknown part of the file /pages/stockin_add.php. The manipulation of the argument prod_name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

SQLi in Campcodes Sales & Inventory System 1.0 via prod_name
CVE-2025-4707 9.8 - Critical - May 15, 2025

A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /pages/transaction_add.php. The manipulation of the argument prod_name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Campcodes Sales & Inventory Sys 1.0 SQLi via discount param
CVE-2025-4708 9.8 - Critical - May 15, 2025

A vulnerability classified as critical has been found in Campcodes Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/sales_add.php. The manipulation of the argument discount leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Critical SQLi via ID in Customer Update page of Campcodes SIS 1.0
CVE-2025-4503 9.8 - Critical - May 10, 2025

A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. This issue affects some unknown processing of the file /pages/customer_update.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

CVE-2025-4502: Critical SQLi in Campcodes Sales & Inventory 1.0 - creditor_add
CVE-2025-4502 9.8 - Critical - May 10, 2025

A vulnerability has been found in Campcodes Sales and Inventory System 1.0 and classified as critical. This vulnerability affects unknown code of the file /pages/creditor_add.php. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Campcodes Sales And Inventory System or by Campcodes? Click the Watch button to subscribe.

Campcodes
Vendor

subscribe