Code Projects Code Projects

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Code Projects product.

RSS Feeds for Code Projects security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Code Projects products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Code Projects Sorted by Most Security Vulnerabilities since 2018

Code Projects Library System20 vulnerabilities

Code Projects Chat System18 vulnerabilities

Code Projects Job Recruitment16 vulnerabilities

Code Projects Blood Bank12 vulnerabilities

Code Projects Modern Bag11 vulnerabilities

Code Projects Voting System7 vulnerabilities

Code Projects Farmacia2 vulnerabilities

By the Year

In 2026 there have been 292 vulnerabilities in Code Projects with an average score of 6.1 out of ten. Last year, in 2025 Code Projects had 461 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Code Projects in 2026 could surpass last years number. Last year, the average CVE base score was greater by 1.41




Year Vulnerabilities Average Score
2026 292 6.09
2025 461 7.51
2024 191 8.50
2023 37 7.29
2022 1 9.80

It may take a day or so for new Code Projects vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Code Projects Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-16220 Jul 19, 2026
XSS in code-projects Online Examination System 1.0 /account.php A vulnerability has been found in code-projects Online Examination System 1.0. This vulnerability affects unknown code of the file /account.php?q=quiz. Such manipulation of the argument eid/n/t leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Online Examination System
CVE-2026-16014 Jul 17, 2026
SQLi in Hospital Bed Management System 1.0 Login Form A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the component Login Form. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Hospital Bed Management System
CVE-2026-15678 Jul 14, 2026
code-projects Online Job Portal 1.0 XSS remote via DetailJob.php A security vulnerability has been detected in code-projects Online Job Portal 1.0. This impacts an unknown function of the file /Admin/DetailJob.php. The manipulation leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
Online Job Portal
CVE-2026-15677 Jul 14, 2026
code-projects Online Job Portal 1.0 PHP Unrestricted File Upload CVE-2026-15677 A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a manipulation of the argument txtFile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
Online Job Portal
CVE-2026-15676 Jul 14, 2026
SQL Injection in /Admin/DeleteUser.php of code-projects Online Job Portal v1.0 A security flaw has been discovered in code-projects Online Job Portal up to 1.0. The impacted element is an unknown function of the file /Admin/DeleteUser.php. Performing a manipulation results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Online Job Portal
CVE-2026-15675 Jul 14, 2026
Online Job Portal 1.0: Remote SQLi via UserId in /Admin/EditUser.php A vulnerability was identified in code-projects Online Job Portal 1.0. The affected element is an unknown function of the file /Admin/EditUser.php. Such manipulation of the argument UserId leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
Online Job Portal
CVE-2026-15137 Jul 09, 2026
SQL Injection in Interview Management System 1.0 View.php (ID Parameter) A weakness has been identified in code-projects Interview Management System 1.0. This vulnerability affects unknown code of the file \inc\classes\View.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Interview Management System
CVE-2026-15135 Jul 08, 2026
SQLi in /edit_food_items.php (Online Food Order Sys 1.0) A security flaw has been discovered in code-projects Online Food Order System 1.0. This affects an unknown part of the file /edit_food_items.php. The manipulation of the argument update results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Online Food Order System
CVE-2026-14769 Jul 05, 2026
Remote SQLi via Bankname in pay.php (Real State Services 1.0) A security vulnerability has been detected in code-projects Real State Services 1.0. This issue affects some unknown processing of the file /pay.php. Such manipulation of the argument Bankname leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Real State Services
CVE-2026-14768 Jul 05, 2026
SQLi via 'loc' in Real State Services 1.0 builderHome.php (code-projects) A weakness has been identified in code-projects Real State Services 1.0. This vulnerability affects unknown code of the file /builderHome.php. This manipulation of the argument loc causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
Real State Services
CVE-2026-14764 Jul 05, 2026
Hotel & Tourism Reservation 1.0 /admin/add_event.php SQLi (Event Mgmt) A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. This impacts an unknown function of the file /admin/add_event.php of the component Event Management Page. Such manipulation of the argument fdetails leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Hotel And Tourism Reservation
CVE-2026-14763 Jul 05, 2026
Hotel & Tourism Reservation 1.0 SQLi via tour param Tour Reservations Page A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. This affects an unknown function of the file /admin/tour_reserves.php of the component Tour Reservations Page. This manipulation of the argument tour causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
Hotel And Tourism Reservation
CVE-2026-14762 Jul 05, 2026
Hotel & Tourism Reservation 1.0 (code-projects) SQLi via delete param in rooms.php A vulnerability was detected in code-projects Hotel and Tourism Reservation 1.0. The impacted element is an unknown function of the file /admin/rooms.php of the component Room Management Page. The manipulation of the argument delete results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
Hotel And Tourism Reservation
CVE-2026-14756 Jul 05, 2026
SQLi in /admin/add_tour.php (delete_image) of Hotel & Tourism Reservation 1.0 A vulnerability was found in code-projects Hotel and Tourism Reservation 1.0. Affected by this issue is some unknown functionality of the file /admin/add_tour.php of the component Tour Management Page. The manipulation of the argument delete_image results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
Hotel And Tourism Reservation
CVE-2026-14755 Jul 05, 2026
SQLi via /admin/reservations.php in Hotel and Tourism Reservation 1.0 A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/reservations.php of the component Reservations Management Page. The manipulation of the argument delete leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Hotel And Tourism Reservation
CVE-2026-14754 Jul 05, 2026
SQLi in Hotel & Tourism Reservation 1.0 /admin/add_room.php A flaw has been found in code-projects Hotel and Tourism Reservation 1.0. Affected is an unknown function of the file /admin/add_room.php. Executing a manipulation of the argument delete_image/edit/description/number/price/rooms/type can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.
Hotel And Tourism Reservation
CVE-2026-14747 Jul 05, 2026
CVE-2026-14747: Remote PHP SQLi in Real State Services 1.0 addprojectsale.php A vulnerability was detected in code-projects Real State Services 1.0. Affected by this vulnerability is an unknown functionality of the file /addprojectsale.php. The manipulation of the argument amen results in sql injection. The attack can be launched remotely.
Real State Services
CVE-2026-14746 Jul 05, 2026
PHP Remote SQLi in code-projects RealStateServices 1.0 addprojectrent.php A security vulnerability has been detected in code-projects Real State Services 1.0. Affected is an unknown function of the file /addprojectrent.php. The manipulation of the argument amen leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
Real State Services
CVE-2026-14745 Jul 05, 2026
SQLi via ID in /single-list_rent.php (Real State Services 1.0) A weakness has been identified in code-projects Real State Services 1.0. This impacts an unknown function of the file /single-list_rent.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
Real State Services
CVE-2026-14744 Jul 05, 2026
Remote SQLi via loc param in /normalHomeRent.php of Real State Services 1.0 A security flaw has been discovered in code-projects Real State Services 1.0. This affects an unknown function of the file /normalHomeRent.php. Performing a manipulation of the argument loc results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
Real State Services
CVE-2026-14743 Jul 05, 2026
Remote SQLi in Real State Services 1.0 normalHomeSale.php (php) A vulnerability was identified in code-projects Real State Services 1.0. The impacted element is an unknown function of the file /normalHomeSale.php. Such manipulation of the argument loc leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
Real State Services
CVE-2026-14735 Jul 05, 2026
Smart Parking System 1.0: Remote SQLi via parkings.php Arg Manipulation A vulnerability has been found in code-projects Smart Parking System 1.0. The affected element is an unknown function of the file /parkings/parkings.php. Such manipulation of the argument street/city/status leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
Smart Parking System
CVE-2026-14706 Jul 05, 2026
Online Examination 1.0 SQLi in Quiz Creation Feature A vulnerability was identified in code-projects Online Examination 1.0. This affects an unknown part of the file /update.php?q=addquiz of the component Quiz Creation Feature. The manipulation of the argument name/total/right/wrong/time/tag/desc leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
Online Examination
CVE-2026-14705 Jul 05, 2026
SQL Injection in Online Exam 1.0 via head.php (uname/password) A vulnerability was determined in code-projects Online Examination 1.0. Affected by this issue is some unknown functionality of the file head.php. Executing a manipulation of the argument uname/password can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.
Online Examination
CVE-2026-14701 Jul 05, 2026
SQLi in code-projects Internship Mgmt System 1.0 Password Change Endpoint A vulnerability was detected in code-projects Internship Management System 1.0. This affects an unknown function of the file employer/details/change_password.php of the component Password Change Endpoint. The manipulation of the argument Current results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.
Internship Management System
CVE-2026-14700 Jul 05, 2026
SQLi in Employer Login Endpoint of Internship Management System 1.0 A security vulnerability has been detected in code-projects Internship Management System 1.0. The impacted element is an unknown function of the file employer/login.php of the component Employer Login Endpoint. The manipulation of the argument email/password leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Internship Management System
CVE-2026-14660 Jul 04, 2026
SQLi in code-projects Online Job Portal 1.0 login.php via txtUser/txtPass A vulnerability was found in code-projects Online Job Portal 1.0. The affected element is an unknown function of the file login.php. Performing a manipulation of the argument txtUser/txtPass results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.
Online Job Portal
CVE-2026-14658 Jul 04, 2026
SQLi in code-projects Assessment Management 1.0 via smarksrange[] - remote A vulnerability was detected in code-projects Assessment Management 1.0. This vulnerability affects unknown code of the file /lecturer/marking-scheme.php. The manipulation of the argument smarksrange[] results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
Assessment Management
CVE-2026-14657 Jul 04, 2026
SQLi in Assessment Management 1.0 DB Query Handler A flaw has been found in code-projects Assessment Management 1.0. This issue affects some unknown processing of the file /lecturer/marking-scheme.php of the component Database Query Handler. This manipulation of the argument squestions[] causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
Assessment Management
CVE-2026-14656 Jul 04, 2026
Assessment Management 1.0 remove-user.php XSS via ID A security vulnerability has been detected in code-projects Assessment Management 1.0. This affects an unknown part of the file /admin/remove-user.php. The manipulation of the argument ID leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
Assessment Management
CVE-2026-14655 Jul 04, 2026
XSS Remote in Assessment Management 1.0 admin/view-users.php A weakness has been identified in code-projects Assessment Management 1.0. Affected by this issue is some unknown functionality of the file admin/view-users.php. Executing a manipulation of the argument User can lead to cross site scripting. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
Assessment Management
CVE-2026-14649 Jul 04, 2026
SQL Injection in test_input of code-projects Online Voting System 1.0 A vulnerability was detected in code-projects Online Voting System 1.0. Impacted is the function test_input of the file /saveVote.php. Performing a manipulation of the argument voterName/voterEmail/voterID/selectedCandidate results in sql injection. The attack can be initiated remotely.
Online Voting System
CVE-2026-14648 Jul 04, 2026
Online Voting Sys. 0.x/1.0: SQLi via test_input in /authentication.php (Login) A security vulnerability has been detected in code-projects Online Voting System up to 0.x/1.0. This issue affects the function test_input of the file /authentication.php of the component Login. Such manipulation of the argument adminUserName/adminPassword leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Online Voting System
CVE-2026-13567 Jun 29, 2026
XSS /Frontend/Feedback.php via POST args (fname,femail,faddress,fmessage) in OMS 1.0 A security flaw has been discovered in code-projects Online Music Site 1.0. This affects an unknown part of the file /Frontend/Feedback.php of the component POST Request Handler. The manipulation of the argument fname/femail/faddress/fmessage results in cross site scripting. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Online Music Site
CVE-2026-13559 Jun 29, 2026
SQLi in Real State Services 1.0 /single-list_sale.php ID A weakness has been identified in code-projects Real State Services 1.0. Impacted is an unknown function of the file /single-list_sale.php?action=add. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
Real State Services
CVE-2026-13504 Jun 28, 2026
code-projects PMS 1.0 XSS in mail.php A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the component Mail Compose Page. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
Project Management System
CVE-2026-11490 Jun 08, 2026
SQLi via /Frontend/Search.php Category in codeprojects OMS 1.0 A vulnerability was determined in code-projects Online Music Site 1.0. This issue affects some unknown processing of the file /Frontend/Search.php. This manipulation of the argument Category causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Online Music Site
CVE-2026-11489 Jun 08, 2026
SQLi AdminDeleteAlbum.php in Online Music Site 1.0 (CVE-2026-11489) A vulnerability was found in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /Administrator/PHP/AdminDeleteAlbum.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.
Online Music Site
CVE-2026-11488 Jun 08, 2026
SQL Injection in POST Handler of Simple Flight Ticket Booking System 1.0 A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown part of the file checkUser.php of the component POST Parameter Handler. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Simple Flight Ticket Booking System
CVE-2026-11344 Jun 05, 2026
Vehicle Management System 1.0: Unrestricted File Upload Newdriver.php Photo A vulnerability was found in code-projects Vehicle Management System 1.0. This impacts an unknown function of the file newdriver.php of the component New Driver Registration Form. Performing a manipulation of the argument photo results in unrestricted upload. The attack may be initiated remotely. The exploit has been made public and could be used.
Vehicle Management System
CVE-2026-11342 Jun 05, 2026
Hotel and Tourism Reservation System 1.0 SQLi via details.php A vulnerability has been found in code-projects Hotel and Tourism Reservation System 1.0. This affects an unknown function of the file /details.php. Such manipulation of the argument room leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Hotel Tourism Reservation System
CVE-2026-10620 Jun 02, 2026
SQLi via eid/did in Student Admission System 1.0 index.php remote A flaw has been found in code-projects Student Admission System 1.0. Affected is an unknown function of the file /index.php. This manipulation of the argument eid/did causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Student Admission System
CVE-2026-10299 Jun 01, 2026
Remote RCE via delid in viewdoctortimings.php (code-projects VHS 1.0) A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. This manipulation of the argument delid causes improper control of resource identifiers. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Online Hospital Management System
CVE-2026-10290 Jun 01, 2026
Hotel & Tourism Reservation System 1.0: SQLi via tour.php GET Param A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tour.php of the component GET Parameter Handler. Executing a manipulation of the argument tour can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
Hotel Tourism Reservation System
CVE-2026-10289 Jun 01, 2026
Hotel and Tourism Reservation System 1.0 XSS via tour.php Args A security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0. Impacted is an unknown function of the file /ht/tour.php. Performing a manipulation of the argument name /email /people /number results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Hotel Tourism Reservation System
CVE-2026-10288 Jun 01, 2026
Improper Auth via Password Manip in Hotel & Tourism Res 1.0 Admin Login A vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This issue affects the function password_verify of the file /admin/login.php of the component Admin Login. Such manipulation of the argument Password leads to improper authentication. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Hotel Tourism Reservation System
CVE-2026-10262 Jun 01, 2026
SQLi in Real State Services 1.0 - Login Component PHP A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Real State Services
CVE-2026-10243 Jun 01, 2026
Smart Parking System 1.0 Auth Bypass via Admin Endpoint (pre-1.0) A security vulnerability has been detected in code-projects Smart Parking System 1.0. Affected is an unknown function of the component Admin Endpoint. Such manipulation leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Multiple endpoints are affected.
Smart Parking System
CVE-2026-10209 Jun 01, 2026
SQLi in Online Hospital Mgt 1.0 Appt Handler (editid) A vulnerability has been found in code-projects Online Hospital Management System 1.0. Affected is an unknown function of the file appointmentdetail.php of the component Appointment Handler. The manipulation of the argument editid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Online Hospital Management System
CVE-2026-10208 Jun 01, 2026
Online Hospital Management System SQLi in login_user A flaw has been found in code-projects Online Hospital Management System 1.php. This impacts the function login_user of the file login_1.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
Online Hospital Management System
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.