Code Projects
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Code Projects product.
RSS Feeds for Code Projects security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Code Projects products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Code Projects Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 312 vulnerabilities in Code Projects with an average score of 6.1 out of ten. Last year, in 2025 Code Projects had 461 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Code Projects in 2026 could surpass last years number. Last year, the average CVE base score was greater by 1.40
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 312 | 6.10 |
| 2025 | 461 | 7.51 |
| 2024 | 191 | 8.50 |
| 2023 | 37 | 7.29 |
| 2022 | 1 | 9.80 |
It may take a day or so for new Code Projects vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Code Projects Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-76990 | Aug 20, 2026 |
SQLi in code-projects Simple Inventory System 1.0 /delete.phpA vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file /delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-76799 | Aug 20, 2026 |
Remote File Access via SQL DB Backup Handler in Login Reg System 1.0A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the file /loginsystem/database/login_registration_system.sql of the component SQL Database Backup Handler. This manipulation causes files or directories accessible. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-76764 | Aug 20, 2026 |
EMS 1.0 Sqli in /process/aprocess.php AdminLogin via mailuidA flaw has been found in code-projects Employee Management System 1.0. The impacted element is an unknown function of the file /process/aprocess.php of the component Admin Login Endpoint. This manipulation of the argument mailuid causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. |
|
| CVE-2026-76762 | Aug 19, 2026 |
Remote SQLi in code-projects Assessment Management 1.0 via /welcome.php useridA vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an unknown function of the file /welcome.php. The manipulation of the argument userid results in sql injection. The attack may be launched remotely. The exploit is now public and may be used. |
|
| CVE-2026-76574 | Aug 19, 2026 |
Hospital Information System 1.0 Remote SQLi via User LoginA flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the function User::login of the file includes/users/UsersController.php of the component User Login Handler. This manipulation of the argument email causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. |
|
| CVE-2026-75986 | Aug 19, 2026 |
Online Job Portal System 1.0 Password Recovery SQLi via ForPass.phpA vulnerability has been found in code-projects Online Job Portal System 1.0. The impacted element is an unknown function of the file /ForPass.php of the component Password Recovery. Such manipulation of the argument txtUserName leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-75778 | Aug 18, 2026 |
A vulnerability was identified in code-projects Task Management System 1.0A vulnerability was identified in code-projects Task Management System 1.0. This affects the function Operation::select_with_multiple_condition of the file /index.php of the component Login Form. Such manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-19998 | Aug 17, 2026 |
CVE-2026-19998 PHP XSS in code-projects OSS 1.0 offersmail.php email argA weakness has been identified in code-projects Online Shopping System 1.0. Impacted is an unknown function of the file offersmail.php. Executing a manipulation of the argument email can lead to cross site scripting. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-19923 | Aug 16, 2026 |
SQLi in Online Shopping System 1.0 /checkout_process.php via total_countA weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /checkout_process.php. Executing a manipulation of the argument total_count can lead to sql injection. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-19922 | Aug 16, 2026 |
Online Shopping System 1.0 XSS via amount_1 in checkout.phpA security flaw has been discovered in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /checkout.php. Performing a manipulation of the argument amount_1 results in cross site scripting. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-19921 | Aug 16, 2026 |
SQLi via /homeaction.php cat_id in code-projects Online Shopping System 1.0A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /homeaction.php. Such manipulation of the argument cat_id leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-19920 | Aug 15, 2026 |
SQLi in codeprojects OSS 1.0 via /action.php proId (remote)A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown function of the file /action.php. This manipulation of the argument proId causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-19919 | Aug 15, 2026 |
CVE-2026-19919: Online Shopping System 1.0 - Remote SQLi in /login.phpA vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login. The manipulation of the argument email results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. |
|
| CVE-2026-19917 | Aug 15, 2026 |
CVE-2026-19917: SQLi via checkbox in delete_food_items1.php of OOS 1.0A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unknown function of the file delete_food_items1.php. Executing a manipulation of the argument checkbox can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used. |
|
| CVE-2026-19916 | Aug 15, 2026 |
XSS in edit_food_items.php (dname) - Online Food Order System 1.0A vulnerability was detected in code-projects Online Food Order System 1.0. The affected element is an unknown function of the file edit_food_items.php. Performing a manipulation of the argument dname results in cross site scripting. Remote exploitation of the attack is possible. The exploit is now public and may be used. |
|
| CVE-2026-19378 | Aug 09, 2026 |
Code-Projects TMS 1.0 XSS in CommentSave.phpA vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the file /user/CommentSave.php. The manipulation of the argument comment/task_id/mineId/recId/myName/myImage results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used. |
|
| CVE-2026-19345 | Aug 09, 2026 |
Task Mgmt Sys 1.0 remote auth bypass via UpdateTaskStatus.phpA vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manipulation of the argument task_id/val results in missing authorization. It is possible to launch the attack remotely. The exploit has been made public and could be used. |
|
| CVE-2026-19344 | Aug 09, 2026 |
Code-Projects Task Management Sys 1.0 SQLi via task_id in comment_count_user.phpA vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/comment_count_user.php. The manipulation of the argument task_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-19343 | Aug 09, 2026 |
Task Management System 1.0 SQLi Vulnerability in admin/AdminLogin.phpA flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/AdminLogin.php. Executing a manipulation of the argument email/password can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. |
|
| CVE-2026-19342 | Aug 09, 2026 |
Task Management System 1.0 Improper Auth via Password in Login.php (remote)A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument Password results in improper authentication. The attack is possible to be carried out remotely. The exploit is now public and may be used. |
|
| CVE-2026-16220 | Jul 19, 2026 |
XSS in code-projects Online Examination System 1.0 /account.phpA vulnerability has been found in code-projects Online Examination System 1.0. This vulnerability affects unknown code of the file /account.php?q=quiz. Such manipulation of the argument eid/n/t leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-16014 | Jul 17, 2026 |
SQLi in Hospital Bed Management System 1.0 Login FormA vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the component Login Form. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. |
|
| CVE-2026-15678 | Jul 14, 2026 |
code-projects Online Job Portal 1.0 XSS remote via DetailJob.phpA security vulnerability has been detected in code-projects Online Job Portal 1.0. This impacts an unknown function of the file /Admin/DetailJob.php. The manipulation leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-15677 | Jul 14, 2026 |
code-projects Online Job Portal 1.0 PHP Unrestricted File Upload CVE-2026-15677A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a manipulation of the argument txtFile can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-15676 | Jul 14, 2026 |
SQL Injection in /Admin/DeleteUser.php of code-projects Online Job Portal v1.0A security flaw has been discovered in code-projects Online Job Portal up to 1.0. The impacted element is an unknown function of the file /Admin/DeleteUser.php. Performing a manipulation results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-15675 | Jul 14, 2026 |
Online Job Portal 1.0: Remote SQLi via UserId in /Admin/EditUser.phpA vulnerability was identified in code-projects Online Job Portal 1.0. The affected element is an unknown function of the file /Admin/EditUser.php. Such manipulation of the argument UserId leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-15137 | Jul 09, 2026 |
SQL Injection in Interview Management System 1.0 View.php (ID Parameter)A weakness has been identified in code-projects Interview Management System 1.0. This vulnerability affects unknown code of the file \inc\classes\View.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-15135 | Jul 08, 2026 |
SQLi in /edit_food_items.php (Online Food Order Sys 1.0)A security flaw has been discovered in code-projects Online Food Order System 1.0. This affects an unknown part of the file /edit_food_items.php. The manipulation of the argument update results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-14769 | Jul 05, 2026 |
Remote SQLi via Bankname in pay.php (Real State Services 1.0)A security vulnerability has been detected in code-projects Real State Services 1.0. This issue affects some unknown processing of the file /pay.php. Such manipulation of the argument Bankname leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-14768 | Jul 05, 2026 |
SQLi via 'loc' in Real State Services 1.0 builderHome.php (code-projects)A weakness has been identified in code-projects Real State Services 1.0. This vulnerability affects unknown code of the file /builderHome.php. This manipulation of the argument loc causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-14764 | Jul 05, 2026 |
Hotel & Tourism Reservation 1.0 /admin/add_event.php SQLi (Event Mgmt)A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. This impacts an unknown function of the file /admin/add_event.php of the component Event Management Page. Such manipulation of the argument fdetails leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-14763 | Jul 05, 2026 |
Hotel & Tourism Reservation 1.0 SQLi via tour param Tour Reservations PageA flaw has been found in code-projects Hotel and Tourism Reservation 1.0. This affects an unknown function of the file /admin/tour_reserves.php of the component Tour Reservations Page. This manipulation of the argument tour causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. |
|
| CVE-2026-14762 | Jul 05, 2026 |
Hotel & Tourism Reservation 1.0 (code-projects) SQLi via delete param in rooms.phpA vulnerability was detected in code-projects Hotel and Tourism Reservation 1.0. The impacted element is an unknown function of the file /admin/rooms.php of the component Room Management Page. The manipulation of the argument delete results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. |
|
| CVE-2026-14756 | Jul 05, 2026 |
SQLi in /admin/add_tour.php (delete_image) of Hotel & Tourism Reservation 1.0A vulnerability was found in code-projects Hotel and Tourism Reservation 1.0. Affected by this issue is some unknown functionality of the file /admin/add_tour.php of the component Tour Management Page. The manipulation of the argument delete_image results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. |
|
| CVE-2026-14755 | Jul 05, 2026 |
SQLi via /admin/reservations.php in Hotel and Tourism Reservation 1.0A vulnerability has been found in code-projects Hotel and Tourism Reservation 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/reservations.php of the component Reservations Management Page. The manipulation of the argument delete leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-14754 | Jul 05, 2026 |
SQLi in Hotel & Tourism Reservation 1.0 /admin/add_room.phpA flaw has been found in code-projects Hotel and Tourism Reservation 1.0. Affected is an unknown function of the file /admin/add_room.php. Executing a manipulation of the argument delete_image/edit/description/number/price/rooms/type can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. |
|
| CVE-2026-14747 | Jul 05, 2026 |
CVE-2026-14747: Remote PHP SQLi in Real State Services 1.0 addprojectsale.phpA vulnerability was detected in code-projects Real State Services 1.0. Affected by this vulnerability is an unknown functionality of the file /addprojectsale.php. The manipulation of the argument amen results in sql injection. The attack can be launched remotely. |
|
| CVE-2026-14746 | Jul 05, 2026 |
PHP Remote SQLi in code-projects RealStateServices 1.0 addprojectrent.phpA security vulnerability has been detected in code-projects Real State Services 1.0. Affected is an unknown function of the file /addprojectrent.php. The manipulation of the argument amen leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-14745 | Jul 05, 2026 |
SQLi via ID in /single-list_rent.php (Real State Services 1.0)A weakness has been identified in code-projects Real State Services 1.0. This impacts an unknown function of the file /single-list_rent.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-14744 | Jul 05, 2026 |
Remote SQLi via loc param in /normalHomeRent.php of Real State Services 1.0A security flaw has been discovered in code-projects Real State Services 1.0. This affects an unknown function of the file /normalHomeRent.php. Performing a manipulation of the argument loc results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-14743 | Jul 05, 2026 |
Remote SQLi in Real State Services 1.0 normalHomeSale.php (php)A vulnerability was identified in code-projects Real State Services 1.0. The impacted element is an unknown function of the file /normalHomeSale.php. Such manipulation of the argument loc leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. |
|
| CVE-2026-14735 | Jul 05, 2026 |
Smart Parking System 1.0: Remote SQLi via parkings.php Arg ManipulationA vulnerability has been found in code-projects Smart Parking System 1.0. The affected element is an unknown function of the file /parkings/parkings.php. Such manipulation of the argument street/city/status leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-14706 | Jul 05, 2026 |
Online Examination 1.0 SQLi in Quiz Creation FeatureA vulnerability was identified in code-projects Online Examination 1.0. This affects an unknown part of the file /update.php?q=addquiz of the component Quiz Creation Feature. The manipulation of the argument name/total/right/wrong/time/tag/desc leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-14705 | Jul 05, 2026 |
SQL Injection in Online Exam 1.0 via head.php (uname/password)A vulnerability was determined in code-projects Online Examination 1.0. Affected by this issue is some unknown functionality of the file head.php. Executing a manipulation of the argument uname/password can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-14701 | Jul 05, 2026 |
SQLi in code-projects Internship Mgmt System 1.0 Password Change EndpointA vulnerability was detected in code-projects Internship Management System 1.0. This affects an unknown function of the file employer/details/change_password.php of the component Password Change Endpoint. The manipulation of the argument Current results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. |
|
| CVE-2026-14700 | Jul 05, 2026 |
SQLi in Employer Login Endpoint of Internship Management System 1.0A security vulnerability has been detected in code-projects Internship Management System 1.0. The impacted element is an unknown function of the file employer/login.php of the component Employer Login Endpoint. The manipulation of the argument email/password leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-14660 | Jul 04, 2026 |
SQLi in code-projects Online Job Portal 1.0 login.php via txtUser/txtPassA vulnerability was found in code-projects Online Job Portal 1.0. The affected element is an unknown function of the file login.php. Performing a manipulation of the argument txtUser/txtPass results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. |
|
| CVE-2026-14658 | Jul 04, 2026 |
SQLi in code-projects Assessment Management 1.0 via smarksrange[] - remoteA vulnerability was detected in code-projects Assessment Management 1.0. This vulnerability affects unknown code of the file /lecturer/marking-scheme.php. The manipulation of the argument smarksrange[] results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. |
|
| CVE-2026-14657 | Jul 04, 2026 |
SQLi in Assessment Management 1.0 DB Query HandlerA flaw has been found in code-projects Assessment Management 1.0. This issue affects some unknown processing of the file /lecturer/marking-scheme.php of the component Database Query Handler. This manipulation of the argument squestions[] causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. |
|
| CVE-2026-14656 | Jul 04, 2026 |
Assessment Management 1.0 remove-user.php XSS via IDA security vulnerability has been detected in code-projects Assessment Management 1.0. This affects an unknown part of the file /admin/remove-user.php. The manipulation of the argument ID leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. |
|