Leave Management System Itsourcecode Leave Management System

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Itsourcecode Leave Management System.

By the Year

In 2026 there have been 5 vulnerabilities in Itsourcecode Leave Management System with an average score of 5.6 out of ten. Last year, in 2025 Leave Management System had 2 security vulnerabilities published. That is, 3 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.22.

Year Vulnerabilities Average Score
2026 5 5.62
2025 2 5.40

It may take a day or so for new Leave Management System vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Itsourcecode Leave Management System Security Vulnerabilities

CVE-2026-93963
CVE-2026-93963 5.3 - Medium - September 20, 2026

A security vulnerability has been detected in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/department/controller.php. The manipulation of the argument DEPTID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

SQL Injection

A flaw has been found in itsourcecode Leave Management System 1.0
CVE-2026-92526 5.3 - Medium - September 16, 2026

A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/leave/index.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.

SQL Injection

A vulnerability has been found in itsourcecode Leave Management System 1.0
CVE-2026-92364 5.3 - Medium - September 16, 2026

A vulnerability has been found in itsourcecode Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /module/employee/index.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

SQL Injection

A vulnerability was identified in itsourcecode Leave Management System 1.0
CVE-2026-90796 5.3 - Medium - September 14, 2026

A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/company/index.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.

SQL Injection

CVE-2026-90789
CVE-2026-90789 6.9 - Medium - September 14, 2026

A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Executing a manipulation of the argument user_email can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

SQL Injection

itsourcecode LMS 1.0 XSS in Query Parameter Handler via Redirect (ID)
CVE-2025-11433 3.5 - Low - October 08, 2025

A security flaw has been discovered in itsourcecode Leave Management System 1.0. This impacts the function redirect of the file /module/employee/controller.php?action=reset of the component Query Parameter Handler. Performing a manipulation of the argument ID results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.

XSS

SQLi in itsourcecode Leave Management System 1.0 /reset.php employid param Remote
CVE-2025-11432 7.3 - High - October 08, 2025

A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /reset.php. Such manipulation of the argument employid leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.

SQL Injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Itsourcecode Leave Management System or by Itsourcecode? Click the Watch button to subscribe.

subscribe