Code Projects
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Code Projects product.
RSS Feeds for Code Projects security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Code Projects products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Code Projects Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 350 vulnerabilities in Code Projects with an average score of 6.1 out of ten. Last year, in 2025 Code Projects had 461 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Code Projects in 2026 could surpass last years number. Last year, the average CVE base score was greater by 1.38
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 350 | 6.12 |
| 2025 | 461 | 7.51 |
| 2024 | 191 | 8.50 |
| 2023 | 37 | 7.29 |
| 2022 | 1 | 9.80 |
It may take a day or so for new Code Projects vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Code Projects Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-93980 | Sep 20, 2026 |
Internship Mgmt Sys 1.0: SQLi via Password in /admin/login.phpA weakness has been identified in code-projects Internship Management System 1.0. This vulnerability affects unknown code of the file /admin/login.php of the component Admin Login Form. Executing a manipulation of the argument Password can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-93979 | Sep 20, 2026 |
SQL Injection in code-projects Internship Management System 1.0 /employer/login.phpA security flaw has been discovered in code-projects Internship Management System 1.0. This affects an unknown part of the file /employer/login.php. Performing a manipulation of the argument Password results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-93978 | Sep 20, 2026 |
CVE-2026-93978: SQLi via /login.php Password in code-projects IMS 1.0A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of the argument Password leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-93977 | Sep 20, 2026 |
XSS in code-projects Assessment Mgt 1.0 (lecturer/add-single-mark.php)A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this vulnerability is an unknown functionality of the file lecturer/add-single-mark.php. This manipulation of the argument mark causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-93976 | Sep 20, 2026 |
CVE-2026-93976: XSS in Assessment Management 1.0 (admin/add-user.php)A vulnerability was found in code-projects Assessment Management 1.0. Affected is an unknown function of the file admin/add-user.php. The manipulation of the argument level results in cross site scripting. The attack may be launched remotely. The exploit has been made public and could be used. |
|
| CVE-2026-93975 | Sep 20, 2026 |
Assessment Management 1.0 XSS in admin/edit-user.phpA vulnerability has been found in code-projects Assessment Management 1.0. This impacts an unknown function of the file admin/edit-user.php of the component User Editing. The manipulation of the argument name/sname/email/username/password/id leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-92926 | Sep 17, 2026 |
SQLi in code-projects Matrimonial System 1.0 writepartnerprefsA vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preference.php. Such manipulation of the argument education leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-92366 | Sep 16, 2026 |
A vulnerability was determined in code-projects Matrimonial System 1.0A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search.php of the component Regular Search. This manipulation of the argument sex/mothertongue/maritialstatus/country/state/religion/agemin/agemax causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-91854 | Sep 15, 2026 |
A vulnerability was identified in code-projects Record Management System 1.0A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the file main/reg.php. Such manipulation of the argument desc leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-86519 | Sep 08, 2026 |
code-projects Student CrudOp 1.0 Backup File Handler Info DisclosureA vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handler. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has been made public and could be used. |
|
| CVE-2026-86518 | Sep 08, 2026 |
SQL Injection in Student CRUD Op 1.0 via ID in edit.phpA vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-86302 | Sep 07, 2026 |
Info Disclosure in code-projects HIS SQL Backup Handler v1.0A vulnerability was found in code-projects Hospital Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /HIS/his.sql of the component SQL Database Backup File Handler. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possible. The exploit has been made public and could be used. |
|
| CVE-2026-86301 | Sep 07, 2026 |
XSS in code-projects HIS 1.0 editPatient.php Patient ManagementA vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. Such manipulation of the argument ID leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-86217 | Sep 06, 2026 |
Info Disclosure in Hotel & Tourism Reservation 1.0 DB Backup via file attackA vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information disclosure. The attack may be launched remotely. The exploit is now public and may be used. |
|
| CVE-2026-86216 | Sep 06, 2026 |
Hotel and Tourism Reservation 1.0 XSS via room param in details.phpA security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an unknown function of the file /ht/details.php. The manipulation of the argument room leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-86181 | Sep 06, 2026 |
Task Management System 1.0 XSS via lname in UpdateUserProfile.phpA vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the component User Profile Update. The manipulation of the argument lname results in cross site scripting. The attack can be launched remotely. The exploit has been made public and could be used. |
|
| CVE-2026-86180 | Sep 06, 2026 |
SQLi in Task Management System 1.0 /index.php Login componentA vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The manipulation of the argument email leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-86179 | Sep 06, 2026 |
Daily Expense Manager 1.0 DABH Info Disclosure VulnerabilityA flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup Handler. Executing a manipulation can lead to information disclosure. It is possible to launch the attack remotely. The exploit has been published and may be used. |
|
| CVE-2026-86168 | Sep 06, 2026 |
code-projects CMS 1.0 SQLi via login.php user_name remoteA security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument user_name results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-85643 | Sep 04, 2026 |
Code-Projects Online Shopping 1.0 SQLi via mysqli_query in admin/adduser.phpA flaw has been found in code-projects Online Shopping System 1.0. Impacted is the function mysqli_query of the file admin/adduser.php. Executing a manipulation of the argument mobile can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. |
|
| CVE-2026-85517 | Sep 04, 2026 |
Vehicle Management System 1.0 SQL Backup Handler Remote Info DisclosureA flaw has been found in code-projects Vehicle Management System 1.0. The impacted element is an unknown function of the file /vehicle_management.sql of the component SQL Database Backup File Handler. Executing a manipulation can lead to information disclosure. It is possible to launch the attack remotely. The exploit has been published and may be used. |
|
| CVE-2026-85516 | Sep 04, 2026 |
Vehicle Management System 1.0 SQLi via busid in /busprofile.php (Remote)A vulnerability was detected in code-projects Vehicle Management System 1.0. The affected element is an unknown function of the file /busprofile.php. Performing a manipulation of the argument busid results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. |
|
| CVE-2026-85403 | Sep 04, 2026 |
Doctor Appointment System 1.0 SQLi in /contactus.phpA flaw has been found in code-projects Doctor Appointment System 1.0. This issue affects some unknown processing of the file /contactus.php. This manipulation of the argument firstname causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. |
|
| CVE-2026-85402 | Sep 04, 2026 |
Doctor Appointment System 1.0: doc_id SQLi in /patient/booking.phpA vulnerability was detected in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient/booking.php. The manipulation of the argument doc_id results in sql injection. The attack may be launched remotely. The exploit is now public and may be used. |
|
| CVE-2026-85399 | Sep 04, 2026 |
SQLi via PrespController ID in Hospital Information System 1.0 (PHP)A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by this vulnerability is the function getSinglePresp of the file includes/presp/PrespController.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-85398 | Sep 04, 2026 |
Hospital Information System 1.0 SQLi in viewReq.php ID parameterA vulnerability was identified in code-projects Hospital Information System 1.0. Affected is the function viewReq of the file viewReq.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-85397 | Sep 04, 2026 |
Remote SQLi in findBySearch (addReq.php) of Hospital Information System 1.0A vulnerability was determined in code-projects Hospital Information System 1.0. This impacts the function findBySearch of the file addReq.php. This manipulation of the argument Search causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-85225 | Sep 03, 2026 |
Doctor Appointment System 1.0 Remote SQLi via patient_login.phpA vulnerability was identified in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient_login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-82701 | Aug 31, 2026 |
SQLi via 'keyword' in action.php of code-projects Online Shopping System 1.0A vulnerability was determined in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /action.php of the component Search Functionality. This manipulation of the argument keyword causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-82700 | Aug 31, 2026 |
XSS in codeprojects Online Shopping System 1.0 NewsletterSubscriptionA vulnerability was found in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /offersmail.php of the component Newsletter Subscription. The manipulation of the argument email results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used. |
|
| CVE-2026-82625 | Aug 31, 2026 |
Simple Inventory System 1.0 XSS via last_name in /register.php (User Registration)A vulnerability has been found in code-projects Simple Inventory System 1.0. This affects an unknown part of the file /register.php of the component User Registration. Such manipulation of the argument last_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-82624 | Aug 31, 2026 |
Simple Inventory System 1.0 DB Backup File Handler Info DisclosureA flaw has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file inventorymanagement.sql of the component Database Backup File Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been published and may be used. |
|
| CVE-2026-82622 | Aug 31, 2026 |
Employee Leave Managing System 1.0 XSS in Profile Update (editaction.php)A security vulnerability has been detected in code-projects Employee Leave Managing System 1.0. Affected is an unknown function of the file /EmpManageSys/editaction.php of the component Employee Profile Update. The manipulation of the argument Name leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-79845 | Aug 25, 2026 |
SQL Injection in Simple Inventory System 1.0 edit.php via IDA vulnerability was identified in code-projects Simple Inventory System 1.0. This vulnerability affects unknown code of the file /InventoryManagement/edit.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-79793 | Aug 25, 2026 |
XSS in code-projects Online Shopping System 1.0 via /admin/sumit_form.phpA vulnerability has been found in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/sumit_form.php. Such manipulation of the argument Success leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-78144 | Aug 23, 2026 |
Barangay Resident Profiling Mgmt Sys 1.0 Auth Bypass via ID in Boarder MgtA vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /boarders.php of the component Boarder Management Module. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-78143 | Aug 23, 2026 |
Barangay Resident Profiling Management System 1.0 SQLi via resident_search.phpA vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file residents.php of the component Resident Search Functionality. This manipulation of the argument Search causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-78142 | Aug 23, 2026 |
BRMS 1.0 - Auth Bypass via resident_id (Restore/Delete)A vulnerability was found in code-projects Barangay Resident Profiling Management System 1.0. This impacts an unknown function of the file /archived_records.php of the component Restore/Delete. The manipulation of the argument resident_id results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. |
|
| CVE-2026-76990 | Aug 20, 2026 |
SQLi in code-projects Simple Inventory System 1.0 /delete.phpA vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file /delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-76799 | Aug 20, 2026 |
Remote File Access via SQL DB Backup Handler in Login Reg System 1.0A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the file /loginsystem/database/login_registration_system.sql of the component SQL Database Backup Handler. This manipulation causes files or directories accessible. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-76764 | Aug 20, 2026 |
EMS 1.0 Sqli in /process/aprocess.php AdminLogin via mailuidA flaw has been found in code-projects Employee Management System 1.0. The impacted element is an unknown function of the file /process/aprocess.php of the component Admin Login Endpoint. This manipulation of the argument mailuid causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. |
|
| CVE-2026-76762 | Aug 19, 2026 |
Remote SQLi in code-projects Assessment Management 1.0 via /welcome.php useridA vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an unknown function of the file /welcome.php. The manipulation of the argument userid results in sql injection. The attack may be launched remotely. The exploit is now public and may be used. |
|
| CVE-2026-76574 | Aug 19, 2026 |
Hospital Information System 1.0 Remote SQLi via User LoginA flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the function User::login of the file includes/users/UsersController.php of the component User Login Handler. This manipulation of the argument email causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. |
|
| CVE-2026-75986 | Aug 19, 2026 |
Online Job Portal System 1.0 Password Recovery SQLi via ForPass.phpA vulnerability has been found in code-projects Online Job Portal System 1.0. The impacted element is an unknown function of the file /ForPass.php of the component Password Recovery. Such manipulation of the argument txtUserName leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-75778 | Aug 18, 2026 |
SQLi in code-projects Task Mgmt Sys 1.0 Login Form via email paramA vulnerability was identified in code-projects Task Management System 1.0. This affects the function Operation::select_with_multiple_condition of the file /index.php of the component Login Form. Such manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-19998 | Aug 17, 2026 |
CVE-2026-19998 PHP XSS in code-projects OSS 1.0 offersmail.php email argA weakness has been identified in code-projects Online Shopping System 1.0. Impacted is an unknown function of the file offersmail.php. Executing a manipulation of the argument email can lead to cross site scripting. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-19923 | Aug 16, 2026 |
SQLi in Online Shopping System 1.0 /checkout_process.php via total_countA weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /checkout_process.php. Executing a manipulation of the argument total_count can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-19922 | Aug 16, 2026 |
Online Shopping System 1.0 XSS via amount_1 in checkout.phpA security flaw has been discovered in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /checkout.php. Performing a manipulation of the argument amount_1 results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-19921 | Aug 16, 2026 |
SQLi via /homeaction.php cat_id in code-projects Online Shopping System 1.0A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /homeaction.php. Such manipulation of the argument cat_id leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-19920 | Aug 15, 2026 |
SQLi in codeprojects OSS 1.0 via /action.php proId (remote)A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown function of the file /action.php. This manipulation of the argument proId causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. |
|