Fabianros Fabianros

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Fabianros product.

RSS Feeds for Fabianros security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Fabianros products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Fabianros Sorted by Most Security Vulnerabilities since 2018

Fabianros Chat System9 vulnerabilities

Fabianros Simple Forum8 vulnerabilities

Fabianros E Commerce Website4 vulnerabilities

Fabianros Job Portal3 vulnerabilities

Fabianros Online Quiz Site3 vulnerabilities

Fabianros E Commerce Site3 vulnerabilities

Fabianros Online Book Shop2 vulnerabilities

Fabianros Shopping Portal1 vulnerability

Fabianros Online Polling1 vulnerability

Fabianros Eblog Site1 vulnerability

Fabianros Atm Banking1 vulnerability

By the Year

In 2026 there have been 0 vulnerabilities in Fabianros. Last year, in 2025 Fabianros had 104 security vulnerabilities published. Right now, Fabianros is on track to have less security vulnerabilities in 2026 than it did last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 104 8.34
2024 53 8.87
2023 5 9.06

It may take a day or so for new Fabianros vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Fabianros Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2025-8859 Aug 11, 2025
Unrestricted File Upload RCE via admin/save-slider.php in eBlog Site 1.0 A vulnerability was identified in code-projects eBlog Site 1.0. Affected by this vulnerability is an unknown functionality of the file /native/admin/save-slider.php of the component File Upload Module. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Eblog Site
CVE-2025-8501 Aug 03, 2025
Human Resource Integrated System 1.0: XSS via content in action.php A vulnerability classified as problematic has been found in code-projects Human Resource Integrated System 1.0. Affected is an unknown function of the file /insert-and-view/action.php. The manipulation of the argument content leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Human Resource Integrated System
CVE-2025-8500 Aug 03, 2025
CRITICAL SQLi via action.php in Human Resource Integrated System 1.0 A vulnerability was found in code-projects Human Resource Integrated System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /insert-and-view/action.php. The manipulation of the argument content leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Human Resource Integrated System
CVE-2025-52327 Aug 01, 2025
Restaurant Order System 1.0 SQLi via payment.php Local SQL Injection vulnerability in Restaurant Order System 1.0 allows a local attacker to obtain sensitive information via the payment.php file
Restaurant Order System
CVE-2025-7756 Jul 17, 2025
Code-Projects E-Commerce Site 1.0 XSRF Remote Vulnerability A vulnerability classified as problematic has been found in code-projects E-Commerce Site 1.0. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
E Commerce Site
CVE-2025-7754 Jul 17, 2025
Critical SQLi via itr_no in code-projects PRMS 1.0 /xray_form.php A vulnerability was found in code-projects Patient Record Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /xray_form.php. The manipulation of the argument itr_no leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Patient Record Management System
CVE-2025-7607 Jul 14, 2025
Simple Shopping Cart 1.0 SQLi via order_price in save_order.php A vulnerability, which was classified as critical, has been found in code-projects Simple Shopping Cart 1.0. This issue affects some unknown processing of the file /Customers/save_order.php. The manipulation of the argument order_price leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Simple Shopping Cart
CVE-2025-7608 Jul 14, 2025
Critical Remote SQLi in Simple Shopping Cart 1.0 A vulnerability, which was classified as critical, was found in code-projects Simple Shopping Cart 1.0. Affected is an unknown function of the file /userlogin.php. The manipulation of the argument user_email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Simple Shopping Cart
CVE-2025-7609 Jul 14, 2025
Simple Shopping Cart 1.0 SQLi via register.php (ruser_email) A vulnerability has been found in code-projects Simple Shopping Cart 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /register.php. The manipulation of the argument ruser_email leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Simple Shopping Cart
CVE-2025-7477 Jul 12, 2025
Simple Car Rental System 1.0 Unrestricted File Upload in /admin/add_cars.php A vulnerability, which was classified as critical, has been found in code-projects Simple Car Rental System 1.0. This issue affects some unknown processing of the file /admin/add_cars.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Simple Car Rental System
CVE-2025-7476 Jul 12, 2025
SQL Injection in Simple Car Rental System 1.0 /admin/approve.php A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. This vulnerability affects unknown code of the file /admin/approve.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Simple Car Rental System
CVE-2025-7475 Jul 12, 2025
Simple Car Rental Sys 1.0: SQLi via /pay.php mpesa (remote) A vulnerability classified as critical has been found in code-projects Simple Car Rental System 1.0. This affects an unknown part of the file /pay.php. The manipulation of the argument mpesa leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Simple Car Rental System
CVE-2025-7210 Jul 09, 2025
Unrestricted Upload via admin/profile_update.php in Fabian Ros LMs 2.0 A vulnerability was found in code-projects/Fabian Ros Library Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/profile_update.php. The manipulation of the argument photo leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Library Management System
CVE-2025-7190 Jul 08, 2025
Unrestricted File Upload in code-projects LMS 2.0 (/admin/student_edit_photo.php) A vulnerability, which was classified as critical, was found in code-projects Library Management System 2.0. This affects an unknown part of the file /admin/student_edit_photo.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Library Management System
CVE-2025-7188 Jul 08, 2025
Code-Projects Chat System 1.0 Sqli in /user/addmember.php via ID A vulnerability classified as critical was found in code-projects Chat System 1.0. Affected by this vulnerability is an unknown functionality of the file /user/addmember.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Chat System
CVE-2025-7189 Jul 08, 2025
Code-Projects Chat System 1.0: SQLi via /user/send_message.php (Remote) A vulnerability, which was classified as critical, has been found in code-projects Chat System 1.0. Affected by this issue is some unknown functionality of the file /user/send_message.php. The manipulation of the argument msg leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Chat System
CVE-2025-7186 Jul 08, 2025
CVE-2025-7186: Code-Projects Chat 1.0 SQLi via /user/fetch_chat.php A vulnerability was found in code-projects Chat System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /user/fetch_chat.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Chat System
CVE-2025-7187 Jul 08, 2025
SQLi in code-projects Chat System 1.0 /user/fetch_member.php ID param A vulnerability classified as critical has been found in code-projects Chat System 1.0. Affected is an unknown function of the file /user/fetch_member.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Chat System
CVE-2025-7175 Jul 08, 2025
Unrestricted Upload via photo in code-projects E-Commerce Site 1.0 CVE-2025-7175 A vulnerability was found in code-projects E-Commerce Site 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/users_photo.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
E Commerce Site
CVE-2025-6866 Jun 29, 2025
Simple Forum 1.0 Path Traversal Remote via /forum_downloadfile.php A vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. This vulnerability affects unknown code of the file /forum_downloadfile.php. The manipulation of the argument filename leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Simple Forum
CVE-2025-6850 Jun 29, 2025
SQLi via 'File' in /forum1.php of code-projects Simple Forum 1.0 A vulnerability has been found in code-projects Simple Forum 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /forum1.php. The manipulation of the argument File leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Simple Forum
CVE-2025-6849 Jun 29, 2025
CVE-2025-6849: Simple Forum 1.0 XSS via forum_edit1.php text arg A vulnerability, which was classified as problematic, was found in code-projects Simple Forum 1.0. Affected is an unknown function of the file /forum_edit1.php. The manipulation of the argument text leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Simple Forum
CVE-2025-6848 Jun 29, 2025
Unrestricted File Upload in Simple Forum 1.0 via /forum1.php A vulnerability, which was classified as critical, has been found in code-projects Simple Forum 1.0. This issue affects some unknown processing of the file /forum1.php. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Simple Forum
CVE-2025-6847 Jun 29, 2025
Simple Forum 1.0 - SQLi in /forum_edit.php via iii param A vulnerability classified as critical was found in code-projects Simple Forum 1.0. This vulnerability affects unknown code of the file /forum_edit.php. The manipulation of the argument iii leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Simple Forum
CVE-2025-6845 Jun 29, 2025
Remote SQLi via /register1.php in Simple Forum 1.0 – Critical A vulnerability was found in code-projects Simple Forum 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /register1.php. The manipulation of the argument User leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Simple Forum
CVE-2025-6846 Jun 29, 2025
Critical SQLi in Simple Forum 1.0 via /forum_viewfile.php A vulnerability classified as critical has been found in code-projects Simple Forum 1.0. This affects an unknown part of the file /forum_viewfile.php. The manipulation of the argument Name leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Simple Forum
CVE-2025-6844 Jun 29, 2025
Simple Forum 1.0 - Critical SQLi via /signin.php User A vulnerability was found in code-projects Simple Forum 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /signin.php. The manipulation of the argument User leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Simple Forum
CVE-2025-6458 Jun 22, 2025
SQLi in Online Hotel Reservation System 1.0 via admin/execedituser.php A vulnerability has been found in code-projects Online Hotel Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/execedituser.php. The manipulation of the argument userid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Online Hotel Reservation System
CVE-2025-6456 Jun 22, 2025
Online Hotel Reservation Sys 1.0: SQLi via /reservation/order.php Start arg A vulnerability, which was classified as critical, has been found in code-projects Online Hotel Reservation System 1.0. Affected by this issue is some unknown functionality of the file /reservation/order.php. The manipulation of the argument Start leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Online Hotel Reservation System
CVE-2025-6457 Jun 22, 2025
CVE-2025-6457: Code-Projects OHR 1.0 Demo.php SQLi via Start A vulnerability, which was classified as critical, was found in code-projects Online Hotel Reservation System 1.0. This affects an unknown part of the file /reservation/demo.php. The manipulation of the argument Start leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Online Hotel Reservation System
CVE-2025-6455 Jun 22, 2025
OHRS 1.0: /messageexec.php SQLi via Name param A vulnerability classified as critical was found in code-projects Online Hotel Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file /messageexec.php. The manipulation of the argument Name leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Online Hotel Reservation System
CVE-2025-6451 Jun 22, 2025
Critical SQLi in code-projects SOHR 1.0 /admin/delete_pending.php A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/delete_pending.php. The manipulation of the argument transaction_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
Simple Online Hotel Reservation System
CVE-2025-6449 Jun 22, 2025
Simple Online Hotel Reservation System 1.0: SQLi in /admin/checkout_query.php A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/checkout_query.php. The manipulation of the argument transaction_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Simple Online Hotel Reservation System
CVE-2025-6450 Jun 22, 2025
Critical SQLi in SOHRS 1.0 via transaction_id in /admin/confirm_reserve.php A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/confirm_reserve.php. The manipulation of the argument transaction_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Simple Online Hotel Reservation System
CVE-2025-6448 Jun 22, 2025
SQLi critical in code-projects S.O.HRS 1.0 /admin/delete_room.php A vulnerability has been found in code-projects Simple Online Hotel Reservation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/delete_room.php. The manipulation of the argument room_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Simple Online Hotel Reservation System
CVE-2025-6447 Jun 22, 2025
SQLi in Simple Online Hotel Reservation System 1.0 (admin/index.php) A vulnerability, which was classified as critical, was found in code-projects Simple Online Hotel Reservation System 1.0. Affected is an unknown function of the file /admin/index.php. The manipulation of the argument Username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Simple Online Hotel Reservation System
CVE-2025-6421 Jun 21, 2025
Simple Online Hotel Reservation System 1.0: SQLi /admin/add_account.php (Critical) A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/add_account.php. The manipulation of the argument name/admin_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Simple Online Hotel Reservation System
CVE-2025-6420 Jun 21, 2025
Simple Online Hotel Reservation System 1.0: Critical SQLi via /admin/add_room.php A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/add_room.php. The manipulation of the argument room_type leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Simple Online Hotel Reservation System
CVE-2025-6418 Jun 21, 2025
PHP Simple Online Hotel 1.0 - /admin/edit_query_account.php Remote SQLi A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/edit_query_account.php. The manipulation of the argument Name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Simple Online Hotel Reservation System
CVE-2025-6419 Jun 21, 2025
SQLi in Simple Online Hotel Reservation System 1.0 /admin/edit_room.php (room_type) A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/edit_room.php. The manipulation of the argument room_type leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Simple Online Hotel Reservation System
CVE-2025-6394 Jun 21, 2025
SQLi in Simple Online Hotel Reservation System 1.0 via add_reserve.php (Remote) A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add_reserve.php. The manipulation of the argument firstname leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
Simple Online Hotel Reservation System
CVE-2025-6355 Jun 20, 2025
SourceCodester Online Hotel Reservation 1.0: SQLi in /admin/execeditroom.php A vulnerability has been found in SourceCodester Online Hotel Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/execeditroom.php. The manipulation of the argument userid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Online Hotel Reservation System
CVE-2025-6296 Jun 20, 2025
Hostel Mgmt Sys 1.0 /empty_rooms.php SQLi via search_box A vulnerability was found in code-projects Hostel Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /empty_rooms.php. The manipulation of the argument search_box leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Hostel Management System
CVE-2025-6295 Jun 20, 2025
SQLi in code-projects HostMgmt Sys 1.0 via search_box in allocated_rooms.php A vulnerability was found in code-projects Hostel Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /allocated_rooms.php. The manipulation of the argument search_box leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Hostel Management System
CVE-2025-6293 Jun 20, 2025
Critical Remote SQL Injection via student_roll_no in Hostel Management System 1.0 A vulnerability was found in code-projects Hostel Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /contact_manager.php. The manipulation of the argument student_roll_no leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Hostel Management System
CVE-2025-6294 Jun 20, 2025
Critical SQLi via hostel_name in contact.php – Hostel Management 1.0 A vulnerability was found in code-projects Hostel Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /contact.php. The manipulation of the argument hostel_name leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Hostel Management System
CVE-2025-6161 Jun 17, 2025
SC Simple Food Ordering System 1.0 Unrestricted Upload via editproduct.php A vulnerability, which was classified as critical, was found in SourceCodester Simple Food Ordering System 1.0. Affected is an unknown function of the file /editproduct.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Simple Food Ordering System
CVE-2025-6159 Jun 17, 2025
Remote SQLi via search_box in Hostel Management System 1.0 /allocate_room.php A vulnerability classified as critical was found in code-projects Hostel Management System 1.0. This vulnerability affects unknown code of the file /allocate_room.php. The manipulation of the argument search_box leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Hostel Management System
CVE-2025-5881 Jun 09, 2025
code-projects Chat System <1.0: Remote SQLi via /user/confirm_password.php A vulnerability was found in code-projects Chat System up to 1.0 and classified as critical. This issue affects some unknown processing of the file /user/confirm_password.php. The manipulation of the argument cid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Chat System
CVE-2025-5857 Jun 09, 2025
Patient Record Mgt Sys 1.0 – SQLi in urinalysis_record.php via itr_no (remote) A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /urinalysis_record.php. The manipulation of the argument itr_no leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Patient Record Management System
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.