Oretnom23
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Oretnom23 product.
RSS Feeds for Oretnom23 security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Oretnom23 products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Oretnom23 Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2025 there have been 66 vulnerabilities in Oretnom23 with an average score of 8.1 out of ten. Last year, in 2024 Oretnom23 had 346 security vulnerabilities published. Right now, Oretnom23 is on track to have less security vulnerabilities in 2025 than it did last year. However, the average CVE base score of the vulnerabilities in 2025 is greater by 0.05.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2025 | 66 | 8.08 |
| 2024 | 346 | 8.02 |
| 2023 | 150 | 8.45 |
| 2022 | 64 | 7.35 |
| 2021 | 7 | 8.80 |
It may take a day or so for new Oretnom23 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Oretnom23 Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2025-40682 | Jul 29, 2025 |
HRMS 1.0 SQLi via city/state in /controller/ccity.phpSQL injection vulnerability in Human Resource Management System version 1.0, which allows an attacker to retrieve, create, update and delete databases via the city and state parameters in the /controller/ccity.php endpoint. |
|
| CVE-2025-40683 | Jul 29, 2025 |
Human Resource Management System 1.0: Reflected XSS via 'searccity' in city.phpReflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'searccity' parameter in /city.php. |
|
| CVE-2025-40684 | Jul 29, 2025 |
Reflected XSS in HR Management System 1.0 via searccountryReflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'searccountry' parameter in/country.php. |
|
| CVE-2025-40685 | Jul 29, 2025 |
Human Resource Management System 1.0 Reflected XSS via searcstate in state.phpReflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'searcstate' parameter in/state.php. |
|
| CVE-2025-40686 | Jul 29, 2025 |
HRMS 1.0 XSS: Reflected XSS via employeeidReflected Cross-Site Scripting (XSS) in Human Resource Management System version 1.0. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the 'employeeid' parameter in/detailview.php. |
|
| CVE-2025-6873 | Jun 29, 2025 |
SourceCodester Simple Company Website 1.0 Unrestricted File Upload in Users.phpA vulnerability, which was classified as critical, has been found in SourceCodester Simple Company Website 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=save. The manipulation of the argument img leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6872 | Jun 29, 2025 |
Unrestricted File Upload via img in SourceCodester Simple Company Website 1.0A vulnerability classified as critical was found in SourceCodester Simple Company Website 1.0. This vulnerability affects unknown code of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument img leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6871 | Jun 29, 2025 |
SQLi in SourceCodester Simple Company Website 1.0's Login.phpA vulnerability classified as critical has been found in SourceCodester Simple Company Website 1.0. This affects an unknown part of the file /classes/Login.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6870 | Jun 29, 2025 |
SourceCodester SCSW 1.0: Unrestricted File Upload via img paramA vulnerability was found in SourceCodester Simple Company Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /classes/Content.php?f=service. The manipulation of the argument img leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6869 | Jun 29, 2025 |
SourceCodester Simple Company Site 1.0 SQLi via /admin/testimonials/manage.phpA vulnerability was found in SourceCodester Simple Company Website 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/testimonials/manage.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6868 | Jun 29, 2025 |
Remote SQLi via ID in SourceCodester SCW 1.0 – CriticalA vulnerability was found in SourceCodester Simple Company Website 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/clients/manage.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6867 | Jun 29, 2025 |
SQLi in SourceCodester Simple Comp Site 1.0 (/admin/services/manage.php)A vulnerability was found in SourceCodester Simple Company Website 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/services/manage.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6476 | Jun 22, 2025 |
SourceCodester Gym Management System 1.0 CSRF Remote ExploitA vulnerability was found in SourceCodester Gym Management System 1.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-6161 | Jun 17, 2025 |
SC Simple Food Ordering System 1.0 Unrestricted Upload via editproduct.phpA vulnerability, which was classified as critical, was found in SourceCodester Simple Food Ordering System 1.0. Affected is an unknown function of the file /editproduct.php. The manipulation of the argument photo leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-4937 | May 19, 2025 |
SQLi via mobilenumber in SourceCodester App Visitor Mgmt Sys 1.0/profile.phpA vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. |
|
| CVE-2025-4935 | May 19, 2025 |
SQLi in SourceCodester Stock Mgmt System 1.0 - changePassword.phpA vulnerability was found in SourceCodester Stock Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /php_action/changePassword.php. The manipulation of the argument user_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-4806 | May 16, 2025 |
Remote Critical SQLi in oretnom23 Stock Mgmt System 1.0 via /admin/paramA vulnerability, which was classified as critical, has been found in SourceCodester/oretnom23 Stock Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/?page=back_order/view_bo. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-4787 | May 16, 2025 |
SQLi in /admin/?page=sales/view_sale (Stock Management System 1.0)A vulnerability classified as critical has been found in SourceCodester/oretnom23 Stock Management System 1.0. Affected is an unknown function of the file /admin/?page=sales/view_sale. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-4786 | May 16, 2025 |
SourceCodester oretnom23 Stock Management 1.0 SQLi in return/view_returnA vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/?page=return/view_return. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-4782 | May 16, 2025 |
SQL Injection in SourceCodester Stock Management System 1.0 via IDA vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /sms/admin/?page=receiving/view_receiving&id=1. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-4481 | May 09, 2025 |
Critical SQLi in SourceCodester AVMS 1.0 via /search-result.phpA vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /search-result.php. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-4283 | May 05, 2025 |
SQLi in Stock Management System 1.0 via Username in Login.php (SourceCodester)A vulnerability was found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /classes/Login.php?f=login. The manipulation of the argument Username leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-4282 | May 05, 2025 |
CSRF in SourceCodester Stock Mgt Sys 1.0 /classes/Users.phpA vulnerability has been found in SourceCodester/oretnom23 Stock Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /classes/Users.php?f=save. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-4267 | May 05, 2025 |
SQLi via ID in SourceCodester oretnom23 Stock Mgmt Sys 1.0 PO PageA vulnerability, which was classified as critical, was found in SourceCodester/oretnom23 Stock Management System 1.0. This affects an unknown part of the file /admin/?page=purchase_order/view_po of the component Purchase Order Details Page. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-4173 | May 01, 2025 |
SourceCodester OES 1.0: delete_cart ID Parameter Causing SQLIA vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerability is the function delete_cart of the file /oews/classes/Master.php?f=delete_cart. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-44192 | Apr 30, 2025 |
SQLi in Simple Barangay Management 1.0 via view_clearanceSourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_clearance. |
|
| CVE-2025-44193 | Apr 30, 2025 |
Simple Barangay Mgmt Sys v1.0 SQLi via /admin?view_complaintSourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_complaint. |
|
| CVE-2025-44194 | Apr 30, 2025 |
SQLi in SourceCodester Simple Barangay Mgmt 1.0 view_householdSourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_household. |
|
| CVE-2025-45956 | Apr 29, 2025 |
SQLi in manage_damage.php of Sourcecodester Computer Lab Management System v1.0A SQL injection vulnerability in manage_damage.php in Sourcecodester Computer Laboratory Management System v1.0 allows an authenticated attacker to execute arbitrary SQL commands via the "id" parameter |
|
| CVE-2023-44752 | Apr 22, 2025 |
Auth Bypass in Student Study Center Desk Management v1.0 via GET /admin/login.phpAn issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscdms/admin/login.php. |
|
| CVE-2025-3817 | Apr 19, 2025 |
SourceCodester OES 1.0: Critical SQLi via delete_stockA vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file /oews/classes/Master.php?f=delete_stock. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2024-40068 | Apr 16, 2025 |
SQLi via id param in Sourcecodester Online ID Gen Sys 1.0Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=templates/manage_template&id=1. |
|
| CVE-2024-40069 | Apr 16, 2025 |
Stored XSS in Sourcecodester Online ID Generator 1.0 via POST firstname/lastnameSourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/Users.php?f=save, and the point of vulnerability is in the POST parameter 'firstname' and 'lastname'. |
|
| CVE-2024-40070 | Apr 16, 2025 |
Arbitrary File Upload in Sourcecodester Online ID Gen Sys 1.0Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/Users.php?f=save. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. |
|
| CVE-2024-40071 | Apr 16, 2025 |
AFU in Sourcecodester Online ID Generator 1.0 via SystemSettings.phpSourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. |
|
| CVE-2024-40072 | Apr 16, 2025 |
SQLi in Sourcecodester Online ID Gen 1.0 via id paramSourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1. |
|
| CVE-2024-40073 | Apr 16, 2025 |
SQL Injection via template param in Sourcecodester Online ID Generator v1.0Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4. |
|
| CVE-2024-40074 | Apr 16, 2025 |
Stored XSS via id_generator/forms SystemSettings.php in Sourcecodester Online ID Generator 1.0Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/SystemSettings.php?f=update_settings, and the point of vulnerability is in the POST parameter 'short_name'. |
|
| CVE-2025-3692 | Apr 16, 2025 |
SourceCodester Online Eyewear Shop 1.0 XSS in Master.php via save_productA vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-3589 | Apr 14, 2025 |
SourceCodester Music Class Enrollment System 1.0 Critical SQLi manage_class.phpA vulnerability, which was classified as critical, was found in SourceCodester Music Class Enrollment System 1.0. Affected is an unknown function of the file /manage_class.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-3315 | Apr 06, 2025 |
SQLi in /view-report.php of SourceCodester Apartment Visitor Mgmt 1.0A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /view-report.php. The manipulation of the argument fromdate/todate leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-3314 | Apr 06, 2025 |
Critical SQLi in SourceCodester Apartment Visitor Mgmt Sys 1.0 /forgotpw.phpA vulnerability has been found in SourceCodester Apartment Visitor Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /forgotpw.php. The manipulation of the argument secode leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-3298 | Apr 05, 2025 |
Access Control Failure in Reg. Handler of SourceCodester OES Shop v1.0A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product of the component Registration Handler. The manipulation of the argument email leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-3297 | Apr 05, 2025 |
XSS via brand param in SourceCodester Online Eyewear Shop 1.0A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /classes/Master.php?f=save_product. The manipulation of the argument brand leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. |
|
| CVE-2025-3296 | Apr 05, 2025 |
Critical SQLi in SourceCodester Online Eyewear Shop 1.0 via /classes/Users.phpA vulnerability, which was classified as critical, has been found in SourceCodester Online Eyewear Shop 1.0. This issue affects some unknown processing of the file /classes/Users.php?f=delete_customer. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-3151 | Apr 03, 2025 |
SQLi in SourceCodester Gym Management System 1.0 /signup.php via user_nameA vulnerability was found in SourceCodester Gym Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /signup.php. The manipulation of the argument user_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-3143 | Apr 03, 2025 |
SourceCodester Apartment Visitor Management SQLi via visitor-entry.php (1.0)A vulnerability classified as critical has been found in SourceCodester Apartment Visitor Management System 1.0. Affected is an unknown function of the file /visitor-entry.php. The manipulation of the argument visname/address leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Multiple parameters might be affected. |
|
| CVE-2025-3142 | Apr 03, 2025 |
Critical SQLi in SourceCodester AvMS 1.0 via buildingnoA vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /add-apartment.php. The manipulation of the argument buildingno leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Multiple parameters might be affected. |
|
| CVE-2025-3140 | Apr 03, 2025 |
SQLi in SourceCodester Online Medicine Ordering System 1.0 - /view_category.phpA vulnerability was found in SourceCodester Online Medicine Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file /view_category.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2025-3141 | Apr 03, 2025 |
Critical SQLi in SourceCodester Medicine Ordering System 1.0 /manage_category.phpA vulnerability was found in SourceCodester Online Medicine Ordering System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /manage_category.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |
|