Fabianros
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Fabianros product.
RSS Feeds for Fabianros security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Fabianros products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Fabianros Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 0 vulnerabilities in Fabianros. Last year, in 2025 Fabianros had 104 security vulnerabilities published. Right now, Fabianros is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 104 | 8.34 |
| 2024 | 53 | 8.87 |
| 2023 | 5 | 9.06 |
It may take a day or so for new Fabianros vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Fabianros Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2025-8859 | Aug 11, 2025 |
Unrestricted File Upload RCE via admin/save-slider.php in eBlog Site 1.0A vulnerability was identified in code-projects eBlog Site 1.0. Affected by this vulnerability is an unknown functionality of the file /native/admin/save-slider.php of the component File Upload Module. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-8501 | Aug 03, 2025 |
Human Resource Integrated System 1.0: XSS via content in action.phpA vulnerability classified as problematic has been found in code-projects Human Resource Integrated System 1.0. Affected is an unknown function of the file /insert-and-view/action.php. The manipulation of the argument content leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-8500 | Aug 03, 2025 |
CRITICAL SQLi via action.php in Human Resource Integrated System 1.0A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /insert-and-view/action.php. The manipulation of the argument content leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-52327 | Aug 01, 2025 |
Restaurant Order System 1.0 SQLi via payment.php LocalSQL Injection vulnerability in Restaurant Order System 1.0 allows a local attacker to obtain sensitive information via the payment.php file |
|
| CVE-2025-7756 | Jul 17, 2025 |
Code-Projects E-Commerce Site 1.0 XSRF Remote VulnerabilityA vulnerability classified as problematic has been found in code-projects E-Commerce Site 1.0. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-7754 | Jul 17, 2025 |
Critical SQLi via itr_no in code-projects PRMS 1.0 /xray_form.phpA vulnerability was found in code-projects Patient Record Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /xray_form.php. The manipulation of the argument itr_no leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-7607 | Jul 14, 2025 |
Simple Shopping Cart 1.0 SQLi via order_price in save_order.phpA vulnerability, which was classified as critical, has been found in code-projects Simple Shopping Cart 1.0. This issue affects some unknown processing of the file /Customers/save_order.php. The manipulation of the argument order_price leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-7608 | Jul 14, 2025 |
Critical Remote SQLi in Simple Shopping Cart 1.0A vulnerability, which was classified as critical, was found in code-projects Simple Shopping Cart 1.0. Affected is an unknown function of the file /userlogin.php. The manipulation of the argument user_email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-7609 | Jul 14, 2025 |
Simple Shopping Cart 1.0 SQLi via register.php (ruser_email)A vulnerability has been found in code-projects Simple Shopping Cart 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /register.php. The manipulation of the argument ruser_email leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-7477 | Jul 12, 2025 |
Simple Car Rental System 1.0 Unrestricted File Upload in /admin/add_cars.phpA vulnerability, which was classified as critical, has been found in code-projects Simple Car Rental System 1.0. This issue affects some unknown processing of the file /admin/add_cars.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-7476 | Jul 12, 2025 |
SQL Injection in Simple Car Rental System 1.0 /admin/approve.phpA vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. This vulnerability affects unknown code of the file /admin/approve.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-7475 | Jul 12, 2025 |
Simple Car Rental Sys 1.0: SQLi via /pay.php mpesa (remote)A vulnerability classified as critical has been found in code-projects Simple Car Rental System 1.0. This affects an unknown part of the file /pay.php. The manipulation of the argument mpesa leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-7210 | Jul 09, 2025 |
Unrestricted Upload via admin/profile_update.php in Fabian Ros LMs 2.0A vulnerability was found in code-projects/Fabian Ros Library Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/profile_update.php. The manipulation of the argument photo leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-7190 | Jul 08, 2025 |
Unrestricted File Upload in code-projects LMS 2.0 (/admin/student_edit_photo.php)A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. This affects an unknown part of the file /admin/student_edit_photo.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-7188 | Jul 08, 2025 |
Code-Projects Chat System 1.0 Sqli in /user/addmember.php via IDA vulnerability classified as critical was found in code-projects Chat System 1.0. Affected by this vulnerability is an unknown functionality of the file /user/addmember.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-7189 | Jul 08, 2025 |
Code-Projects Chat System 1.0: SQLi via /user/send_message.php (Remote)A vulnerability, which was classified as critical, has been found in code-projects Chat System 1.0. Affected by this issue is some unknown functionality of the file /user/send_message.php. The manipulation of the argument msg leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-7186 | Jul 08, 2025 |
CVE-2025-7186: Code-Projects Chat 1.0 SQLi via /user/fetch_chat.phpA vulnerability was found in code-projects Chat System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /user/fetch_chat.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-7187 | Jul 08, 2025 |
SQLi in code-projects Chat System 1.0 /user/fetch_member.php ID paramA vulnerability classified as critical has been found in code-projects Chat System 1.0. Affected is an unknown function of the file /user/fetch_member.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-7175 | Jul 08, 2025 |
Unrestricted Upload via photo in code-projects E-Commerce Site 1.0 CVE-2025-7175A vulnerability was found in code-projects E-Commerce Site 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/users_photo.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6866 | Jun 29, 2025 |
Simple Forum 1.0 Path Traversal Remote via /forum_downloadfile.phpA vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. This vulnerability affects unknown code of the file /forum_downloadfile.php. The manipulation of the argument filename leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6850 | Jun 29, 2025 |
SQLi via 'File' in /forum1.php of code-projects Simple Forum 1.0A vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /forum1.php. The manipulation of the argument File leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6849 | Jun 29, 2025 |
CVE-2025-6849: Simple Forum 1.0 XSS via forum_edit1.php text argA vulnerability, which was classified as problematic, was found in code-projects Simple Forum 1.0. Affected is an unknown function of the file /forum_edit1.php. The manipulation of the argument text leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6848 | Jun 29, 2025 |
Unrestricted File Upload in Simple Forum 1.0 via /forum1.phpA vulnerability, which was classified as critical, has been found in code-projects Simple Forum 1.0. This issue affects some unknown processing of the file /forum1.php. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6847 | Jun 29, 2025 |
Simple Forum 1.0 - SQLi in /forum_edit.php via iii paramA vulnerability classified as critical was found in code-projects Simple Forum 1.0. This vulnerability affects unknown code of the file /forum_edit.php. The manipulation of the argument iii leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6845 | Jun 29, 2025 |
Remote SQLi via /register1.php in Simple Forum 1.0 – CriticalA vulnerability was found in code-projects Simple Forum 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /register1.php. The manipulation of the argument User leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6846 | Jun 29, 2025 |
Critical SQLi in Simple Forum 1.0 via /forum_viewfile.phpA vulnerability classified as critical has been found in code-projects Simple Forum 1.0. This affects an unknown part of the file /forum_viewfile.php. The manipulation of the argument Name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6844 | Jun 29, 2025 |
Simple Forum 1.0 - Critical SQLi via /signin.php UserA vulnerability was found in code-projects Simple Forum 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /signin.php. The manipulation of the argument User leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6458 | Jun 22, 2025 |
SQLi in Online Hotel Reservation System 1.0 via admin/execedituser.phpA vulnerability has been found in code-projects Online Hotel Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/execedituser.php. The manipulation of the argument userid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6456 | Jun 22, 2025 |
Online Hotel Reservation Sys 1.0: SQLi via /reservation/order.php Start argA vulnerability, which was classified as critical, has been found in code-projects Online Hotel Reservation System 1.0. Affected by this issue is some unknown functionality of the file /reservation/order.php. The manipulation of the argument Start leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6457 | Jun 22, 2025 |
CVE-2025-6457: Code-Projects OHR 1.0 Demo.php SQLi via StartA vulnerability, which was classified as critical, was found in code-projects Online Hotel Reservation System 1.0. This affects an unknown part of the file /reservation/demo.php. The manipulation of the argument Start leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6455 | Jun 22, 2025 |
OHRS 1.0: /messageexec.php SQLi via Name paramA vulnerability classified as critical was found in code-projects Online Hotel Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file /messageexec.php. The manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6451 | Jun 22, 2025 |
Critical SQLi in code-projects SOHR 1.0 /admin/delete_pending.phpA vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/delete_pending.php. The manipulation of the argument transaction_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. |
|
| CVE-2025-6449 | Jun 22, 2025 |
Simple Online Hotel Reservation System 1.0: SQLi in /admin/checkout_query.phpA vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/checkout_query.php. The manipulation of the argument transaction_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6450 | Jun 22, 2025 |
Critical SQLi in SOHRS 1.0 via transaction_id in /admin/confirm_reserve.phpA vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/confirm_reserve.php. The manipulation of the argument transaction_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6448 | Jun 22, 2025 |
SQLi critical in code-projects S.O.HRS 1.0 /admin/delete_room.phpA vulnerability has been found in code-projects Simple Online Hotel Reservation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/delete_room.php. The manipulation of the argument room_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6447 | Jun 22, 2025 |
SQLi in Simple Online Hotel Reservation System 1.0 (admin/index.php)A vulnerability, which was classified as critical, was found in code-projects Simple Online Hotel Reservation System 1.0. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6421 | Jun 21, 2025 |
Simple Online Hotel Reservation System 1.0: SQLi /admin/add_account.php (Critical)A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/add_account.php. The manipulation of the argument name/admin_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6420 | Jun 21, 2025 |
Simple Online Hotel Reservation System 1.0: Critical SQLi via /admin/add_room.phpA vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/add_room.php. The manipulation of the argument room_type leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6418 | Jun 21, 2025 |
PHP Simple Online Hotel 1.0 - /admin/edit_query_account.php Remote SQLiA vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/edit_query_account.php. The manipulation of the argument Name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6419 | Jun 21, 2025 |
SQLi in Simple Online Hotel Reservation System 1.0 /admin/edit_room.php (room_type)A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/edit_room.php. The manipulation of the argument room_type leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6394 | Jun 21, 2025 |
SQLi in Simple Online Hotel Reservation System 1.0 via add_reserve.php (Remote)A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add_reserve.php. The manipulation of the argument firstname leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. |
|
| CVE-2025-6355 | Jun 20, 2025 |
SourceCodester Online Hotel Reservation 1.0: SQLi in /admin/execeditroom.phpA vulnerability has been found in SourceCodester Online Hotel Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/execeditroom.php. The manipulation of the argument userid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6296 | Jun 20, 2025 |
Hostel Mgmt Sys 1.0 /empty_rooms.php SQLi via search_boxA vulnerability was found in code-projects Hostel Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /empty_rooms.php. The manipulation of the argument search_box leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6295 | Jun 20, 2025 |
SQLi in code-projects HostMgmt Sys 1.0 via search_box in allocated_rooms.phpA vulnerability was found in code-projects Hostel Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /allocated_rooms.php. The manipulation of the argument search_box leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6293 | Jun 20, 2025 |
Critical Remote SQL Injection via student_roll_no in Hostel Management System 1.0A vulnerability was found in code-projects Hostel Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /contact_manager.php. The manipulation of the argument student_roll_no leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6294 | Jun 20, 2025 |
Critical SQLi via hostel_name in contact.php – Hostel Management 1.0A vulnerability was found in code-projects Hostel Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /contact.php. The manipulation of the argument hostel_name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6161 | Jun 17, 2025 |
SC Simple Food Ordering System 1.0 Unrestricted Upload via editproduct.phpA vulnerability, which was classified as critical, was found in SourceCodester Simple Food Ordering System 1.0. Affected is an unknown function of the file /editproduct.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6159 | Jun 17, 2025 |
Remote SQLi via search_box in Hostel Management System 1.0 /allocate_room.phpA vulnerability classified as critical was found in code-projects Hostel Management System 1.0. This vulnerability affects unknown code of the file /allocate_room.php. The manipulation of the argument search_box leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-5881 | Jun 09, 2025 |
code-projects Chat System <1.0: Remote SQLi via /user/confirm_password.phpA vulnerability was found in code-projects Chat System up to 1.0 and classified as critical. This issue affects some unknown processing of the file /user/confirm_password.php. The manipulation of the argument cid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-5857 | Jun 09, 2025 |
Patient Record Mgt Sys 1.0 – SQLi in urinalysis_record.php via itr_no (remote)A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /urinalysis_record.php. The manipulation of the argument itr_no leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|