Code Projects
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Code Projects product.
RSS Feeds for Code Projects security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Code Projects products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Code Projects Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 84 vulnerabilities in Code Projects with an average score of 6.5 out of ten. Last year, in 2025 Code Projects had 461 security vulnerabilities published. Right now, Code Projects is on track to have less security vulnerabilities in 2026 than it did last year. Last year, the average CVE base score was greater by 1.02
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 84 | 6.49 |
| 2025 | 461 | 7.51 |
| 2024 | 191 | 8.50 |
| 2023 | 37 | 7.29 |
| 2022 | 1 | 9.80 |
It may take a day or so for new Code Projects vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Code Projects Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-3763 | Mar 08, 2026 |
Remote XSS in Simple Flight Ticket Booking System 1.0 showhistory.phpA vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. The affected element is an unknown function of the file showhistory.php. The manipulation results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used. |
|
| CVE-2026-3745 | Mar 08, 2026 |
Student Web Portal 1.0 SQLi via profile.php User arg in code-projectsA vulnerability was found in code-projects Student Web Portal 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument User results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. |
|
| CVE-2026-3744 | Mar 08, 2026 |
SQL injection in Student Web Portal 1.0 valreg_passwdation (signup.php)A vulnerability has been found in code-projects Student Web Portal 1.0. This impacts the function valreg_passwdation of the file signup.php. The manipulation of the argument reg_passwd leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-3736 | Mar 08, 2026 |
SQLi in Simple Flight Ticket Booking System 1.0 via SearchResultRoundtrip.phpA vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this issue is some unknown functionality of the file SearchResultRoundtrip.php. Performing a manipulation of the argument from results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. |
|
| CVE-2026-3735 | Mar 08, 2026 |
Simple Flight Ticket Booking 1.0: SearchResultOneway.php SQLiA vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file SearchResultOneway.php. Such manipulation of the argument from leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-3723 | Mar 08, 2026 |
SQLi in Simple Flight Ticket Booking 1.0 /Admindelete.php flightno argA security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown function of the file /Admindelete.php. The manipulation of the argument flightno results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-3711 | Mar 08, 2026 |
code-projects Simple Flight Ticket Booking Sys v1.0 - Remote SQLiA vulnerability was detected in code-projects Simple Flight Ticket Booking System 1.0. Affected is an unknown function of the file /Adminupdate.php. The manipulation of the argument flightno/airplaneid/departure/dtime/arrival/atime/ec/ep/bc/bp results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. |
|
| CVE-2026-3710 | Mar 08, 2026 |
SQLI in code-projects Simple Flight Ticket Booking System 1.0 /Adminadd.phpA security vulnerability has been detected in code-projects Simple Flight Ticket Booking System 1.0. This impacts an unknown function of the file /Adminadd.php. The manipulation of the argument flightno/airplaneid/departure/dtime/arrival/atime/ec/ep/bc/bp leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-3709 | Mar 08, 2026 |
SQL Injection in register.php of Simple Flight Ticket Booking System 1.0A weakness has been identified in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown function of the file /register.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-3708 | Mar 08, 2026 |
SQL Injection in Simple Flight Ticket Booking 1.0 /login.php (Username)A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. The impacted element is an unknown function of the file /login.php. Performing a manipulation of the argument Username results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-3705 | Mar 08, 2026 |
Simple Flight Ticket Booking System 1.0 - SQL Injection in /Adminsearch.phpA vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. This issue affects some unknown processing of the file /Adminsearch.php. The manipulation of the argument flightno results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. |
|
| CVE-2026-2912 | Feb 22, 2026 |
SQLi in Online Reviewer 1.0 via test_id in studentresult-view.phpA vulnerability was found in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/students/assessments/results/studentresult-view.php. The manipulation of the argument test_id results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. |
|
| CVE-2026-2706 | Feb 19, 2026 |
SQLi in Patient Record Mgmt Sys 1.0 via /fecalysis_not.php comp_idA flaw has been found in code-projects Patient Record Management System 1.0. This affects an unknown function of the file /fecalysis_not.php. This manipulation of the argument comp_id causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. |
|
| CVE-2025-70151 | Feb 18, 2026 |
Unrestricted File Upload RCE in Scholars Tracking System 1.0code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-accessible uploads/ directory using the original, user-supplied filename without validating the file type or extension. By uploading a PHP file and then requesting it from /uploads/, an attacker can execute arbitrary PHP code as the web server user. |
|
| CVE-2026-2224 | Feb 09, 2026 |
XSS in code-projects Online Review Sys 1.0 /system/admins/manage/users/btn_functions.phpA vulnerability was detected in code-projects Online Reviewer System 1.0. This affects an unknown part of the file /system/system/admins/manage/users/btn_functions.php. The manipulation of the argument firstname results in cross site scripting. It is possible to launch the attack remotely. The exploit is now public and may be used. |
|
| CVE-2026-2223 | Feb 09, 2026 |
code-projects Online Reviewer System 1.0 index.php SQLi ID paramA security vulnerability has been detected in code-projects Online Reviewer System 1.0. Affected by this issue is some unknown functionality of the file /system/system/students/assessments/pretest/take/index.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-2222 | Feb 09, 2026 |
XSS via firstname in btn_functions.php (1.0)A weakness has been identified in code-projects Online Reviewer System 1.0. Affected by this vulnerability is an unknown functionality of the file /system/system/admins/manage/users/btn_functions.php. Executing a manipulation of the argument firstname can lead to cross site scripting. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-2221 | Feb 09, 2026 |
Online Reviewer System 1.0 Login SQLi via /login/index.php Username RemoteA security flaw has been discovered in code-projects Online Reviewer System 1.0. Affected is an unknown function of the file /login/index.php of the component Login. Performing a manipulation of the argument Username results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-2220 | Feb 09, 2026 |
code-projects ORS 1.0: Remote SQLi via difficulty_idA vulnerability was identified in code-projects Online Reviewer System 1.0. This impacts an unknown function of the file /system/system/admins/assessments/pretest/btn_functions.php. Such manipulation of the argument difficulty_id leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-2214 | Feb 09, 2026 |
CVE-2026-2214 XSS via txtalbum in code-projects Plugin 1.0 (AdminAddAlbum)A weakness has been identified in code-projects for Plugin 1.0. This affects an unknown part of the file /Administrator/PHP/AdminAddAlbum.php. This manipulation of the argument txtalbum causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-2213 | Feb 09, 2026 |
Code-Projects Online Music Site 1.0 Unrestricted File Upload via txtimageA security flaw has been discovered in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/AdminAddAlbum.php. The manipulation of the argument txtimage results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-2212 | Feb 09, 2026 |
SQLi via ID in CodeProjects Online Music Site 1.0 AdminEditCategory.phpA vulnerability was identified in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /Administrator/PHP/AdminEditCategory.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-2211 | Feb 09, 2026 |
SQLi via ID in AdminDeleteCategory.php of Online Music Site 1.0A vulnerability was determined in code-projects Online Music Site 1.0. Affected is an unknown function of the file /Administrator/PHP/AdminDeleteCategory.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-2199 | Feb 09, 2026 |
SQLi in code-projects Online Reviewer System 1.0 via user-delete.phpA security flaw has been discovered in code-projects Online Reviewer System 1.0. The impacted element is an unknown function of the file /reviewer/system/system/admins/manage/users/user-delete.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-2198 | Feb 09, 2026 |
SQL Injection in code-projects Online Reviewer System 1.0 via difficulty_idA vulnerability was identified in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /system/system/admins/assessments/pretest/loaddata.php. Such manipulation of the argument difficulty_id leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-2197 | Feb 09, 2026 |
Code-Projects Online Reviewer System 1.0 SQLi in exam-delete.phpA vulnerability was determined in code-projects Online Reviewer System 1.0. Impacted is an unknown function of the file /system/system/admins/assessments/pretest/exam-delete.php. This manipulation of the argument test_id causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-2196 | Feb 09, 2026 |
SQLi in code-projects Online Reviewer System 1.0 via exam-update.php test_idA vulnerability was found in code-projects Online Reviewer System 1.0. This issue affects some unknown processing of the file /system/system/admins/assessments/pretest/exam-update.php. The manipulation of the argument test_id results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. |
|
| CVE-2026-2195 | Feb 08, 2026 |
SQLi in code-projects Online Reviewer System 1.0 via ID paramA vulnerability has been found in code-projects Online Reviewer System 1.0. This vulnerability affects unknown code of the file /system/system/admins/assessments/pretest/questions-view.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-2176 | Feb 08, 2026 |
CVE-2026-2176: SQLi in code-projects CMS 1.0 index.py (remote)A security vulnerability has been detected in code-projects Contact Management System 1.0. This issue affects some unknown processing of the file index.py. Such manipulation of the argument selecteditem[0] leads to sql injection. The attack can be executed remotely. |
|
| CVE-2026-2174 | Feb 08, 2026 |
Contact Management Sys 1.0 CRUD Endpoint ID Auth Bypass RemoteA security flaw has been discovered in code-projects Contact Management System 1.0. This affects an unknown part of the component CRUD Endpoint. The manipulation of the argument ID results in improper authentication. The attack may be launched remotely. |
|
| CVE-2026-2173 | Feb 08, 2026 |
Code-Projects OES 1.0 SQLi via login.phpA vulnerability was identified in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely. |
|
| CVE-2026-2172 | Feb 08, 2026 |
Remote SQLi in code-projects OAS Admission 1.0 Login EndpointA vulnerability was determined in code-projects Online Application System for Admission 1.0. Affected by this vulnerability is an unknown functionality of the file enrollment/index.php of the component Login Endpoint. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-2171 | Feb 08, 2026 |
Online Student Management System 1.0: SQLi via accounts.php Login (remote)A vulnerability was found in code-projects Online Student Management System 1.0. Affected is an unknown function of the file accounts.php of the component Login. Performing a manipulation of the argument username/password results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. |
|
| CVE-2026-2166 | Feb 08, 2026 |
SQL Injection in Online Reviewer System 1.0 Login ComponentA security vulnerability has been detected in code-projects Online Reviewer System 1.0. The affected element is an unknown function of the file /login/index.php of the component Login. The manipulation of the argument username/password leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-2158 | Feb 08, 2026 |
SQLi in Student Web Portal 1.0 /check_user.php via UsernameA vulnerability was detected in code-projects Student Web Portal 1.0. This impacts an unknown function of the file /check_user.php. Performing a manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely. |
|
| CVE-2026-2156 | Feb 08, 2026 |
XSS in Code-Projects OSM 1.0 /admin/announcement/index.phpA weakness has been identified in code-projects Online Student Management System 1.0. The impacted element is an unknown function of the file /admin/announcement/index.php?view=add of the component Announcement Management Module. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-2133 | Feb 08, 2026 |
code-projects Online Music Site 1.0 Unrestricted Remote File Upload via txtimageA weakness has been identified in code-projects Online Music Site 1.0. Impacted is an unknown function of the file /Administrator/PHP/AdminUpdateCategory.php. This manipulation of the argument txtimage causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-2132 | Feb 08, 2026 |
Online Music Site 1.0 SQLi via txtcat in AdminUpdateCategory.phpA security flaw has been discovered in code-projects Online Music Site 1.0. This issue affects some unknown processing of the file /Administrator/PHP/AdminUpdateCategory.php. The manipulation of the argument txtcat results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-2083 | Feb 07, 2026 |
SQLi in code-projects SNS 1.0 via /delete_post.php (remote ID manipulation)A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file /delete_post.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-2060 | Feb 06, 2026 |
SQLi in EditCampaignForm.php of Simple Blood Donor Management System 1.0A vulnerability was found in code-projects Simple Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /simpleblooddonor/editcampaignform.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. |
|
| CVE-2026-1535 | Jan 28, 2026 |
Online Music Site 1.0 ID-based SQL Injection in AdminReply.phpA security vulnerability has been detected in code-projects Online Music Site 1.0. This impacts an unknown function of the file /Administrator/PHP/AdminReply.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-1534 | Jan 28, 2026 |
SQLi in Online Music Site 1.0 via AdminEditUser.php IDA weakness has been identified in code-projects Online Music Site 1.0. This affects an unknown function of the file /Administrator/PHP/AdminEditUser.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-1533 | Jan 28, 2026 |
Online Music Site 1.0 Remote SQLi via AdminAddCategory.phpA security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PHP/AdminAddCategory.php. The manipulation results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-1443 | Jan 26, 2026 |
code-projects Online Music Site 1.0 SQLi in AdminDeleteUser.phpA flaw has been found in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/AdminDeleteUser.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. |
|
| CVE-2026-1423 | Jan 26, 2026 |
Unrestricted File Upload in code-projects OES 1.0 admin_pic.phpA vulnerability was determined in code-projects Online Examination System 1.0. Affected by this issue is some unknown functionality of the file /admin_pic.php. Executing a manipulation can lead to unrestricted upload. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-1422 | Jan 26, 2026 |
SQLi via User Arg in Login Page of code-projects OES 1.0A vulnerability was found in code-projects Online Examination System 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login Page. Performing a manipulation of the argument User results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. |
|
| CVE-2026-1421 | Jan 26, 2026 |
code-projects OES 1.0 XSS in Add Pages componentA vulnerability has been found in code-projects Online Examination System 1.0. Affected is an unknown function of the component Add Pages. Such manipulation leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-0852 | Jan 12, 2026 |
Remote SQLi via id in Online Music Site 1.0 AdminUpdateUser.phpA security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PHP/AdminUpdateUser.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-0851 | Jan 11, 2026 |
SQLi in Online Music Site 1.0 /AdminAddUser.php via txtusernameA vulnerability was identified in code-projects Online Music Site 1.0. The affected element is an unknown function of the file /Administrator/PHP/AdminAddUser.php. The manipulation of the argument txtusername leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. |
|
| CVE-2026-0850 | Jan 11, 2026 |
CVE-2026-0850: SQLi in IMMS 1.0 admin/delete_activity.phpA vulnerability was determined in code-projects Intern Membership Management System 1.0. Impacted is an unknown function of the file /admin/delete_activity.php. Executing a manipulation of the argument activity_id can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. |