Code Projects
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Code Projects product.
RSS Feeds for Code Projects security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Code Projects products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Code Projects Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 292 vulnerabilities in Code Projects with an average score of 6.1 out of ten. Last year, in 2025 Code Projects had 461 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Code Projects in 2026 could surpass last years number. Last year, the average CVE base score was greater by 1.41
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 292 | 6.09 |
| 2025 | 461 | 7.51 |
| 2024 | 191 | 8.50 |
| 2023 | 37 | 7.29 |
| 2022 | 1 | 9.80 |
It may take a day or so for new Code Projects vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Code Projects Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-16220 | Jul 19, 2026 |
XSS in code-projects Online Examination System 1.0 /account.phpA vulnerability has been found in code-projects Online Examination System 1.0. This vulnerability affects unknown code of the file /account.php?q=quiz. Such manipulation of the argument eid/n/t leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-16014 | Jul 17, 2026 |
SQLi in Hospital Bed Management System 1.0 Login FormA vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the component Login Form. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. |
|
| CVE-2026-15678 | Jul 14, 2026 |
code-projects Online Job Portal 1.0 XSS remote via DetailJob.phpA security vulnerability has been detected in code-projects Online Job Portal 1.0. This impacts an unknown function of the file /Admin/DetailJob.php. The manipulation leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-15677 | Jul 14, 2026 |
code-projects Online Job Portal 1.0 PHP Unrestricted File Upload CVE-2026-15677A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a manipulation of the argument txtFile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-15676 | Jul 14, 2026 |
SQL Injection in /Admin/DeleteUser.php of code-projects Online Job Portal v1.0A security flaw has been discovered in code-projects Online Job Portal up to 1.0. The impacted element is an unknown function of the file /Admin/DeleteUser.php. Performing a manipulation results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-15675 | Jul 14, 2026 |
Online Job Portal 1.0: Remote SQLi via UserId in /Admin/EditUser.phpA vulnerability was identified in code-projects Online Job Portal 1.0. The affected element is an unknown function of the file /Admin/EditUser.php. Such manipulation of the argument UserId leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-15137 | Jul 09, 2026 |
SQL Injection in Interview Management System 1.0 View.php (ID Parameter)A weakness has been identified in code-projects Interview Management System 1.0. This vulnerability affects unknown code of the file \inc\classes\View.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-15135 | Jul 08, 2026 |
SQLi in /edit_food_items.php (Online Food Order Sys 1.0)A security flaw has been discovered in code-projects Online Food Order System 1.0. This affects an unknown part of the file /edit_food_items.php. The manipulation of the argument update results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-14769 | Jul 05, 2026 |
Remote SQLi via Bankname in pay.php (Real State Services 1.0)A security vulnerability has been detected in code-projects Real State Services 1.0. This issue affects some unknown processing of the file /pay.php. Such manipulation of the argument Bankname leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-14768 | Jul 05, 2026 |
SQLi via 'loc' in Real State Services 1.0 builderHome.php (code-projects)A weakness has been identified in code-projects Real State Services 1.0. This vulnerability affects unknown code of the file /builderHome.php. This manipulation of the argument loc causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-14764 | Jul 05, 2026 |
Hotel & Tourism Reservation 1.0 /admin/add_event.php SQLi (Event Mgmt)A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. This impacts an unknown function of the file /admin/add_event.php of the component Event Management Page. Such manipulation of the argument fdetails leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-14763 | Jul 05, 2026 |
Hotel & Tourism Reservation 1.0 SQLi via tour param Tour Reservations PageA flaw has been found in code-projects Hotel and Tourism Reservation 1.0. This affects an unknown function of the file /admin/tour_reserves.php of the component Tour Reservations Page. This manipulation of the argument tour causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. |
|
| CVE-2026-14762 | Jul 05, 2026 |
Hotel & Tourism Reservation 1.0 (code-projects) SQLi via delete param in rooms.phpA vulnerability was detected in code-projects Hotel and Tourism Reservation 1.0. The impacted element is an unknown function of the file /admin/rooms.php of the component Room Management Page. The manipulation of the argument delete results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. |
|
| CVE-2026-14756 | Jul 05, 2026 |
SQLi in /admin/add_tour.php (delete_image) of Hotel & Tourism Reservation 1.0A vulnerability was found in code-projects Hotel and Tourism Reservation 1.0. Affected by this issue is some unknown functionality of the file /admin/add_tour.php of the component Tour Management Page. The manipulation of the argument delete_image results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. |
|
| CVE-2026-14755 | Jul 05, 2026 |
SQLi via /admin/reservations.php in Hotel and Tourism Reservation 1.0A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/reservations.php of the component Reservations Management Page. The manipulation of the argument delete leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-14754 | Jul 05, 2026 |
SQLi in Hotel & Tourism Reservation 1.0 /admin/add_room.phpA flaw has been found in code-projects Hotel and Tourism Reservation 1.0. Affected is an unknown function of the file /admin/add_room.php. Executing a manipulation of the argument delete_image/edit/description/number/price/rooms/type can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. |
|
| CVE-2026-14747 | Jul 05, 2026 |
CVE-2026-14747: Remote PHP SQLi in Real State Services 1.0 addprojectsale.phpA vulnerability was detected in code-projects Real State Services 1.0. Affected by this vulnerability is an unknown functionality of the file /addprojectsale.php. The manipulation of the argument amen results in sql injection. The attack can be launched remotely. |
|
| CVE-2026-14746 | Jul 05, 2026 |
PHP Remote SQLi in code-projects RealStateServices 1.0 addprojectrent.phpA security vulnerability has been detected in code-projects Real State Services 1.0. Affected is an unknown function of the file /addprojectrent.php. The manipulation of the argument amen leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-14745 | Jul 05, 2026 |
SQLi via ID in /single-list_rent.php (Real State Services 1.0)A weakness has been identified in code-projects Real State Services 1.0. This impacts an unknown function of the file /single-list_rent.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-14744 | Jul 05, 2026 |
Remote SQLi via loc param in /normalHomeRent.php of Real State Services 1.0A security flaw has been discovered in code-projects Real State Services 1.0. This affects an unknown function of the file /normalHomeRent.php. Performing a manipulation of the argument loc results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-14743 | Jul 05, 2026 |
Remote SQLi in Real State Services 1.0 normalHomeSale.php (php)A vulnerability was identified in code-projects Real State Services 1.0. The impacted element is an unknown function of the file /normalHomeSale.php. Such manipulation of the argument loc leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. |
|
| CVE-2026-14735 | Jul 05, 2026 |
Smart Parking System 1.0: Remote SQLi via parkings.php Arg ManipulationA vulnerability has been found in code-projects Smart Parking System 1.0. The affected element is an unknown function of the file /parkings/parkings.php. Such manipulation of the argument street/city/status leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-14706 | Jul 05, 2026 |
Online Examination 1.0 SQLi in Quiz Creation FeatureA vulnerability was identified in code-projects Online Examination 1.0. This affects an unknown part of the file /update.php?q=addquiz of the component Quiz Creation Feature. The manipulation of the argument name/total/right/wrong/time/tag/desc leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-14705 | Jul 05, 2026 |
SQL Injection in Online Exam 1.0 via head.php (uname/password)A vulnerability was determined in code-projects Online Examination 1.0. Affected by this issue is some unknown functionality of the file head.php. Executing a manipulation of the argument uname/password can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-14701 | Jul 05, 2026 |
SQLi in code-projects Internship Mgmt System 1.0 Password Change EndpointA vulnerability was detected in code-projects Internship Management System 1.0. This affects an unknown function of the file employer/details/change_password.php of the component Password Change Endpoint. The manipulation of the argument Current results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. |
|
| CVE-2026-14700 | Jul 05, 2026 |
SQLi in Employer Login Endpoint of Internship Management System 1.0A security vulnerability has been detected in code-projects Internship Management System 1.0. The impacted element is an unknown function of the file employer/login.php of the component Employer Login Endpoint. The manipulation of the argument email/password leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-14660 | Jul 04, 2026 |
SQLi in code-projects Online Job Portal 1.0 login.php via txtUser/txtPassA vulnerability was found in code-projects Online Job Portal 1.0. The affected element is an unknown function of the file login.php. Performing a manipulation of the argument txtUser/txtPass results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. |
|
| CVE-2026-14658 | Jul 04, 2026 |
SQLi in code-projects Assessment Management 1.0 via smarksrange[] - remoteA vulnerability was detected in code-projects Assessment Management 1.0. This vulnerability affects unknown code of the file /lecturer/marking-scheme.php. The manipulation of the argument smarksrange[] results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. |
|
| CVE-2026-14657 | Jul 04, 2026 |
SQLi in Assessment Management 1.0 DB Query HandlerA flaw has been found in code-projects Assessment Management 1.0. This issue affects some unknown processing of the file /lecturer/marking-scheme.php of the component Database Query Handler. This manipulation of the argument squestions[] causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. |
|
| CVE-2026-14656 | Jul 04, 2026 |
Assessment Management 1.0 remove-user.php XSS via IDA security vulnerability has been detected in code-projects Assessment Management 1.0. This affects an unknown part of the file /admin/remove-user.php. The manipulation of the argument ID leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-14655 | Jul 04, 2026 |
XSS Remote in Assessment Management 1.0 admin/view-users.phpA weakness has been identified in code-projects Assessment Management 1.0. Affected by this issue is some unknown functionality of the file admin/view-users.php. Executing a manipulation of the argument User can lead to cross site scripting. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-14649 | Jul 04, 2026 |
SQL Injection in test_input of code-projects Online Voting System 1.0A vulnerability was detected in code-projects Online Voting System 1.0. Impacted is the function test_input of the file /saveVote.php. Performing a manipulation of the argument voterName/voterEmail/voterID/selectedCandidate results in sql injection. The attack can be initiated remotely. |
|
| CVE-2026-14648 | Jul 04, 2026 |
Online Voting Sys. 0.x/1.0: SQLi via test_input in /authentication.php (Login)A security vulnerability has been detected in code-projects Online Voting System up to 0.x/1.0. This issue affects the function test_input of the file /authentication.php of the component Login. Such manipulation of the argument adminUserName/adminPassword leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-13567 | Jun 29, 2026 |
XSS /Frontend/Feedback.php via POST args (fname,femail,faddress,fmessage) in OMS 1.0A security flaw has been discovered in code-projects Online Music Site 1.0. This affects an unknown part of the file /Frontend/Feedback.php of the component POST Request Handler. The manipulation of the argument fname/femail/faddress/fmessage results in cross site scripting. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-13559 | Jun 29, 2026 |
SQLi in Real State Services 1.0 /single-list_sale.php IDA weakness has been identified in code-projects Real State Services 1.0. Impacted is an unknown function of the file /single-list_sale.php?action=add. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-13504 | Jun 28, 2026 |
code-projects PMS 1.0 XSS in mail.phpA vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the component Mail Compose Page. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-11490 | Jun 08, 2026 |
SQLi via /Frontend/Search.php Category in codeprojects OMS 1.0A vulnerability was determined in code-projects Online Music Site 1.0. This issue affects some unknown processing of the file /Frontend/Search.php. This manipulation of the argument Category causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-11489 | Jun 08, 2026 |
SQLi AdminDeleteAlbum.php in Online Music Site 1.0 (CVE-2026-11489)A vulnerability was found in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /Administrator/PHP/AdminDeleteAlbum.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. |
|
| CVE-2026-11488 | Jun 08, 2026 |
SQL Injection in POST Handler of Simple Flight Ticket Booking System 1.0A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown part of the file checkUser.php of the component POST Parameter Handler. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-11344 | Jun 05, 2026 |
Vehicle Management System 1.0: Unrestricted File Upload Newdriver.php PhotoA vulnerability was found in code-projects Vehicle Management System 1.0. This impacts an unknown function of the file newdriver.php of the component New Driver Registration Form. Performing a manipulation of the argument photo results in unrestricted upload. The attack may be initiated remotely. The exploit has been made public and could be used. |
|
| CVE-2026-11342 | Jun 05, 2026 |
Hotel and Tourism Reservation System 1.0 SQLi via details.phpA vulnerability has been found in code-projects Hotel and Tourism Reservation System 1.0. This affects an unknown function of the file /details.php. Such manipulation of the argument room leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-10620 | Jun 02, 2026 |
SQLi via eid/did in Student Admission System 1.0 index.php remoteA flaw has been found in code-projects Student Admission System 1.0. Affected is an unknown function of the file /index.php. This manipulation of the argument eid/did causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. |
|
| CVE-2026-10299 | Jun 01, 2026 |
Remote RCE via delid in viewdoctortimings.php (code-projects VHS 1.0)A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. This manipulation of the argument delid causes improper control of resource identifiers. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-10290 | Jun 01, 2026 |
Hotel & Tourism Reservation System 1.0: SQLi via tour.php GET ParamA weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tour.php of the component GET Parameter Handler. Executing a manipulation of the argument tour can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-10289 | Jun 01, 2026 |
Hotel and Tourism Reservation System 1.0 XSS via tour.php ArgsA security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0. Impacted is an unknown function of the file /ht/tour.php. Performing a manipulation of the argument name /email /people /number results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-10288 | Jun 01, 2026 |
Improper Auth via Password Manip in Hotel & Tourism Res 1.0 Admin LoginA vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This issue affects the function password_verify of the file /admin/login.php of the component Admin Login. Such manipulation of the argument Password leads to improper authentication. It is possible to launch the attack remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-10262 | Jun 01, 2026 |
SQLi in Real State Services 1.0 - Login Component PHPA vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-10243 | Jun 01, 2026 |
Smart Parking System 1.0 Auth Bypass via Admin Endpoint (pre-1.0)A security vulnerability has been detected in code-projects Smart Parking System 1.0. Affected is an unknown function of the component Admin Endpoint. Such manipulation leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Multiple endpoints are affected. |
|
| CVE-2026-10209 | Jun 01, 2026 |
SQLi in Online Hospital Mgt 1.0 Appt Handler (editid)A vulnerability has been found in code-projects Online Hospital Management System 1.0. Affected is an unknown function of the file appointmentdetail.php of the component Appointment Handler. The manipulation of the argument editid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-10208 | Jun 01, 2026 |
Online Hospital Management System SQLi in login_userA flaw has been found in code-projects Online Hospital Management System 1.php. This impacts the function login_user of the file login_1.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. |
|