CVEs we hold for Project
Records whose assigning authority named Project as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-9364projectworlds Online Art Gallery Shop adminHome.php sql injectionprojectworlds Online Art Gallery Shop
CVE-2026-92718Nuclei from 3.7.0 before 3.11.1 Template Signature Bypass via Modification-Time-Only Cacheprojectdiscovery nuclei
CVE-2026-8785projectworlds hospital-management-system-in-php GET Parameter update_info.php getAllPatientDetail sql injectionprojectworlds hospital-management-system-in-php
CVE-2026-86238projectworlds Online Examination System Feedback Form feedback.php cross site scriptingprojectworlds Online Examination System
CVE-2026-86226Projectwolds Online Attendance System profile.php cross site scriptingProjectwolds Online Attendance System
CVE-2026-74930WP Project Manager 2.2.0 - 4.0.6 - Subscriber+ User Activity Feed Disclosure via IDORUnknown Project Manager
CVE-2026-74929WP Project Manager < 4.0.7 - Subscriber+ Cross-Project Task Disclosure and Task Board Modification via IDORUnknown Project Manager
CVE-2026-74928WP Project Manager 2.1.0 - 4.0.6 - Unauthenticated Subscriber Account Creation via Trello Import RoutesUnknown Project Manager
CVE-2026-6595ProjectsAndPrograms School Management System HTTP GET Parameter buslocation.php sql injectionProjectsAndPrograms School Management System
CVE-2026-65835Capsule: Incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource…projectcapsule capsule
CVE-2026-65834Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node…projectcapsule capsule
CVE-2026-61833zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletionproject-zot zot
CVE-2026-61795Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to…projectcapsule capsule
CVE-2026-61794Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panicprojectcapsule capsule
CVE-2026-61672Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcementprojectcapsule capsule
CVE-2026-5645projectworlds Car Rental System Parameter pay.php sql injectionprojectworlds Car Rental System
CVE-2026-5637projectworlds Car Rental System Parameter message_admin.php sql injectionprojectworlds Car Rental System
CVE-2026-5634projectworlds Car Rental Project Parameter book_car.php sql injectionprojectworlds Car Rental Project
CVE-2026-55636Capsule: Incomplete fix of CVE-2026-30963: singular/plural typo leaves namespaces/finalize unprotectedprojectcapsule capsule
CVE-2026-5472ProjectsAndPrograms School Management System Profile Picture settings.php unrestricted uploadProjectsAndPrograms School Management System
CVE-2026-53992Reflected XSS in ProjectSend thumbnails-regenerate.php via start_date / end_date ParametersProjectSend
CVE-2026-5368projectworlds Car Rental Project Parameter login.php sql injectionprojectworlds Car Rental Project
CVE-2026-50149Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabledprojectcontour contour
CVE-2026-47325Weak password policy in ProjectsAndPrograms school-management-systemProjectsAndPrograms school-management-system
CVE-2026-47324Stored XSS in Multiple Points in ProjectsAndPrograms school-management-systemProjectsAndPrograms school-management-system
CVE-2026-4626projectworlds Lawyer Management System lawyer_booking.php cross site scriptingprojectworlds Lawyer Management System
CVE-2026-4596projectworlds Lawyer Management System lawyers.php cross site scriptingprojectworlds Lawyer Management System
CVE-2026-4540projectworlds Online Notes Sharing System Parameters login.php sql injectionprojectworlds Online Notes Sharing System
CVE-2026-41645Nuclei: Environment variable disclosure via Response-Derived DSL Expressionsprojectdiscovery nuclei
CVE-2026-3759projectworlds Online Art Gallery Shop adminHome.php sql injectionprojectworlds Online Art Gallery Shop
CVE-2026-3758projectworlds Online Art Gallery Shop adminHome.php sql injectionprojectworlds Online Art Gallery Shop
CVE-2026-3757projectworlds Online Art Gallery Shop pass sql injectionprojectworlds Online Art Gallery Shop
CVE-2026-3477PZ Frontend Manager <= 1.0.6 - Missing Authorization to Arbitrary User Deletion via 'dataType' Parameterprojectzealous01 PZ Frontend Manager
CVE-2026-3406projectworlds Online Art Gallery Shop Registration registration.php sql injectionprojectworlds Online Art Gallery Shop
CVE-2026-31801zot create-only policy allows overwrite attempts of existing latest tag (update permission not required)project-zot zot
CVE-2026-22872Capsule TenantResource RawItems Cluster-Scoped Resource Creation Vulnerabilityprojectcapsule capsule
CVE-2026-2136projectworlds Online Food Ordering System view-ticket.php sql injectionprojectworlds Online Food Ordering System
CVE-2026-1700projectworlds House Rental and Property Listing sms.php cross site scriptingprojectworlds House Rental and Property Listing
CVE-2026-12877Software Issue Manager < 5.1.0 - Unauthenticated SQL Injection via Search ParameterUnknown Project Management, Bug and Issue Tracking Plugin
CVE-2026-10875projectworlds Online Art Gallery Shop Project adminHome.ph sql injectionprojectworlds Online Art Gallery Shop Project
CVE-2026-10874projectworlds Online Art Gallery Shop Project adminHome.php sql injectionprojectworlds Online Art Gallery Shop Project
CVE-2026-0643projectworlds House Rental and Property Listing Signup register.php unrestricted uploadprojectworlds House Rental and Property Listing
CVE-2026-0642projectworlds House Rental and Property Listing complaint.php cross site scriptingprojectworlds House Rental and Property Listing
CVE-2025-9928projectworlds Travel Management System viewcategory.php sql injectionprojectworlds Travel Management System
CVE-2025-9927projectworlds Travel Management System viewpackage.php sql injectionprojectworlds Travel Management System
CVE-2025-9926projectworlds Travel Management System viewsubcategory.php sql injectionprojectworlds Travel Management System
CVE-2025-9925projectworlds Travel Management System detail.php sql injectionprojectworlds Travel Management System
CVE-2025-9924projectworlds Travel Management System enquiry.php sql injectionprojectworlds Travel Management System
CVE-2025-9053projectworlds Travel Management System updatesubcategory.php sql injectionprojectworlds Travel Management System
CVE-2025-9052projectworlds Travel Management System updatepackage.php sql injectionprojectworlds Travel Management System
CVE-2025-9051projectworlds Travel Management System updatecategory.php sql injectionprojectworlds Travel Management System
CVE-2025-9050projectworlds Travel Management System addcategory.php sql injectionprojectworlds Travel Management System
CVE-2025-9047projectworlds Visitor Management System visitor_out.php sql injectionprojectworlds Visitor Management System
CVE-2025-8948projectworlds Visitor Management System front.php sql injectionprojectworlds Visitor Management System
CVE-2025-8947projectworlds Visitor Management System query_data.php sql injectionprojectworlds Visitor Management System
CVE-2025-8946projectworlds Online Notes Sharing Platform login.php sql injectionprojectworlds Online Notes Sharing Platform
CVE-2025-8496projectworlds Online Admission System viewform.php sql injectionprojectworlds Online Admission System
CVE-2025-8471projectworlds Online Admission System adminlogin.php sql injectionprojectworlds Online Admission System
CVE-2025-8436projectworlds Online Admission System viewdoc.php sql injectionprojectworlds Online Admission System
CVE-2025-8338projectworlds Online Admission System adminac.php sql injectionprojectworlds Online Admission System
CVE-2025-8247Projectworlds Online Admission System admin.php sql injectionProjectworlds Online Admission System
CVE-2025-6136Projectworlds Life Insurance Management System insertPayment.php sql injectionProjectworlds Life Insurance Management System
CVE-2025-6135Projectworlds Life Insurance Management System insertNominee.php sql injectionProjectworlds Life Insurance Management System
CVE-2025-6134Projectworlds Life Insurance Management System insertClient.php sql injectionProjectworlds Life Insurance Management System
CVE-2025-6133Projectworlds Life Insurance Management System insertagent.php sql injectionProjectworlds Life Insurance Management System
CVE-2025-59133WordPress Projectopia plugin <= 5.1.25.2 - Insecure Direct Object References (IDOR) vulnerabilityProjectopia
CVE-2025-58755MONAI has path traversal issue that may lead to arbitrary file writesProject-MONAI MONAI
CVE-2025-55205Capsule tenant owners with "patch namespace" permission can hijack system namespaces labelprojectcapsule capsule
CVE-2025-5213projectworlds Responsive E-Learning System delete_file.php sql injectionprojectworlds Responsive E-Learning System
CVE-2025-5008projectworlds Online Time Table Generator add_teacher.php sql injectionprojectworlds Online Time Table Generator
CVE-2025-5004projectworlds Online Time Table Generator add_course.php sql injectionprojectworlds Online Time Table Generator
CVE-2025-5003projectworlds Online Time Table Generator semester_ajax.php sql injectionprojectworlds Online Time Table Generator
CVE-2025-4936projectworlds Online Food Ordering System admin-page.php sql injectionprojectworlds Online Food Ordering System
CVE-2025-4932projectworlds Online Lawyer Management System lawyer_registation.php sql injectionprojectworlds Online Lawyer Management System
CVE-2025-4931projectworlds Online Lawyer Management System user_registation.php sql injectionprojectworlds Online Lawyer Management System
CVE-2025-4928projectworlds Online Lawyer Management System save_lawyer_edit_profile.php sql injectionprojectworlds Online Lawyer Management System
CVE-2025-4837projectworlds Student Project Allocation System make_group_sql.php sql injectionprojectworlds Student Project Allocation System
CVE-2025-4836Projectworlds Life Insurance Management System deleteAgent.php sql injectionProjectworlds Life Insurance Management System
CVE-2025-48257WordPress Projectopia plugin <= 5.1.17 - Broken Access Control VulnerabilityProjectopia
CVE-2025-4739projectworlds Hospital Database Management System medicines_info.php sql injectionprojectworlds Hospital Database Management System
CVE-2025-4706projectworlds Online Examination System Procedure3b_yearwiseVisit.php sql injectionprojectworlds Online Examination System
CVE-2025-4482Project Worlds Student Project Allocation System forgot_password_sql.php sql injectionProject Allocation System
CVE-2025-4058Projectworlds Online Examination System Bloodgroop_process.php sql injectionProjectworlds Online Examination System
CVE-2025-4034projectworlds Online Examination System inser_doc_process.php sql injectionprojectworlds Online Examination System
CVE-2025-3952Projectopia – WordPress Project Management <= 5.1.16 - Missing Authorization to Authenticated (Subscriber+)…Projectopia – Project Management Tool
CVE-2025-32648WordPress Projectopia plugin <= 5.1.24 - Privilege Escalation vulnerabilityProjectopia
CVE-2025-3186projectworlds Online Doctor Appointment Booking System invoice.php sql injectionprojectworlds Online Doctor Appointment Booking System
CVE-2025-3185projectworlds Online Doctor Appointment Booking System patientupdateprofile.php sql injectionprojectworlds Online Doctor Appointment Booking System
CVE-2025-3184projectworlds Online Doctor Appointment Booking System profile.php sql injectionprojectworlds Online Doctor Appointment Booking System
CVE-2025-3183projectworlds Online Doctor Appointment Booking System patientupdateprofile.php sql injectionprojectworlds Online Doctor Appointment Booking System
CVE-2025-3182projectworlds Online Doctor Appointment Booking System getschedule.php sql injectionprojectworlds Online Doctor Appointment Booking System
CVE-2025-3181projectworlds Online Doctor Appointment Booking System appointment.php sql injectionprojectworlds Online Doctor Appointment Booking System
CVE-2025-3180projectworlds Online Doctor Appointment Booking System deleteschedule.php sql injectionprojectworlds Online Doctor Appointment Booking System
CVE-2025-3179projectworlds Online Doctor Appointment Booking System deletepatient.php sql injectionprojectworlds Online Doctor Appointment Booking System
CVE-2025-3178projectworlds Online Doctor Appointment Booking System deleteappointment.php sql injectionprojectworlds Online Doctor Appointment Booking System
CVE-2025-3176Project Worlds Online Lawyer Management System single_lawyer.php sql injectionProject Worlds Online Lawyer Management System
CVE-2025-3175Project Worlds Online Lawyer Management System save_user_edit_profile.php sql injectionProject Worlds Online Lawyer Management System
CVE-2025-3174Project Worlds Online Lawyer Management System searchLawyer.php sql injectionProject Worlds Online Lawyer Management System
CVE-2025-3173Project Worlds Online Lawyer Management System save_booking.php sql injectionProject Worlds Online Lawyer Management System
CVE-2025-3172Project Worlds Online Lawyer Management System lawyer_booking.php sql injectionProject Worlds Online Lawyer Management System
CVE-2025-3171Project Worlds Online Lawyer Management System approve_lawyer.php sql injectionProject Worlds Online Lawyer Management System
CVE-2025-3170Project Worlds Online Lawyer Management System admin_user.php sql injectionProject Worlds Online Lawyer Management System
CVE-2025-3042Project Worlds Online Time Table Generator updateprofile.php unrestricted uploadProject Worlds Online Time Table Generator
CVE-2025-3041Project Worlds Online Time Table Generator updatestudent.php unrestricted uploadProject Worlds Online Time Table Generator
CVE-2025-3040Project Worlds Online Time Table Generator add_student.php unrestricted uploadProject Worlds Online Time Table Generator
CVE-2025-2662Project Worlds Online Time Table Generator studentdashboard.php sql injectionProject Worlds Online Time Table Generator
CVE-2025-2661Project Worlds Online Time Table Generator index.php sql injectionProject Worlds Online Time Table Generator
CVE-2025-2660Project Worlds Online Time Table Generator index.php sql injectionProject Worlds Online Time Table Generator
CVE-2025-2659Project Worlds Online Time Table Generator index.php sql injectionProject Worlds Online Time Table Generator
CVE-2025-2657projectworlds Apartment Visitors Management System front.php sql injectionprojectworlds Apartment Visitors Management System
CVE-2025-2067projectworlds Life Insurance Management System search.php sql injectionprojectworlds Life Insurance Management System
CVE-2025-2066projectworlds Life Insurance Management System updateAgent.php sql injectionprojectworlds Life Insurance Management System
CVE-2025-2065projectworlds Life Insurance Management System editAgent.php sql injectionprojectworlds Life Insurance Management System
CVE-2025-2064projectworlds Life Insurance Management System deletePayment.php sql injectionprojectworlds Life Insurance Management System
CVE-2025-2063projectworlds Life Insurance Management System deleteNominee.php sql injectionprojectworlds Life Insurance Management System
CVE-2025-2062projectworlds Life Insurance Management System clientStatus.php sql injectionprojectworlds Life Insurance Management System
CVE-2025-1965projectworlds Online Hotel Booking login.php sql injectionprojectworlds Online Hotel Booking
CVE-2025-1964projectworlds Online Hotel Booking booknow.php sql injectionprojectworlds Online Hotel Booking
CVE-2025-1963projectworlds Online Hotel Booking reservation.php sql injectionprojectworlds Online Hotel Booking
CVE-2025-1962projectworlds Online Hotel Booking addroom.php sql injectionprojectworlds Online Hotel Booking
CVE-2025-14571projectworlds Advanced Library Management System borrow_book.php sql injectionprojectworlds Advanced Library Management System
CVE-2025-14570projectworlds Advanced Library Management System view_admin.php sql injectionprojectworlds Advanced Library Management System
CVE-2025-14527projectworlds Advanced Library Management System view_book.php sql injectionprojectworlds Advanced Library Management System
CVE-2025-14212projectworlds Advanced Library Management System member_search.php sql injectionprojectworlds Advanced Library Management System
CVE-2025-14211projectworlds Advanced Library Management System delete_book.php sql injectionprojectworlds Advanced Library Management System
CVE-2025-14210projectworlds Advanced Library Management System delete_member.php sql injectionprojectworlds Advanced Library Management System
CVE-2025-13573projectworlds can pass malicious payloads add_book.php unrestricted uploadprojectworlds can pass malicious payloads
CVE-2025-13572projectworlds Advanced Library Management System delete_admin.php sql injectionprojectworlds Advanced Library Management System
CVE-2025-13278projectworlds Advanced Library Management System borrowed_book_search.php sql injectionprojectworlds Advanced Library Management System
CVE-2025-13256projectworlds Advanced Library Management System borrow.php sql injectionprojectworlds Advanced Library Management System
CVE-2025-13255projectworlds Advanced Library Management System book_search.php sql injectionprojectworlds Advanced Library Management System
CVE-2025-13254projectworlds Advanced Library Management System add_member.php sql injectionprojectworlds Advanced Library Management System
CVE-2025-13253projectworlds Advanced Library Management System add_librarian.php sql injectionprojectworlds Advanced Library Management System
CVE-2025-12938projectworlds Online Admission System process_login.php sql injectionprojectworlds Online Admission System
CVE-2025-12876Projectopia – WordPress Project Management <= 5.1.19 - Missing Authorization to Unauthenticated Arbitrary Attachment…Projectopia – Project Management Tool
CVE-2025-12862projectworlds Online Notes Sharing Platform userprofile.php unrestricted uploadprojectworlds Online Notes Sharing Platform
CVE-2025-12237projectworlds Advanced Library Management System index.php sql injectionprojectworlds Advanced Library Management System
CVE-2025-12231projectworlds Expense Management System Expense Categories create cross site scriptingprojectworlds Expense Management System
CVE-2025-12230projectworlds Expense Management System Currency create cross site scriptingprojectworlds Expense Management System
CVE-2025-12229projectworlds Expense Management System Roles Page create cross site scriptingprojectworlds Expense Management System
CVE-2025-12228projectworlds Expense Management System Users Page create cross site scriptingprojectworlds Expense Management System
CVE-2025-12227projectworlds Gate Pass Management System add-pass.php cross site scriptingprojectworlds Gate Pass Management System
CVE-2025-12215projectworlds Online Shopping System login_submit.php sql injectionprojectworlds Online Shopping System
CVE-2025-11661ProjectsAndPrograms School Management System missing authenticationProjectsAndPrograms School Management System
CVE-2025-11660ProjectsAndPrograms School Management System uploadSllyabus.php unrestricted uploadProjectsAndPrograms School Management System
CVE-2025-11659ProjectsAndPrograms School Management System uploadNotes.php unrestricted uploadProjectsAndPrograms School Management System
CVE-2025-11658ProjectsAndPrograms School Management System changeSllyabus.php unrestricted uploadProjectsAndPrograms School Management System
CVE-2025-11657ProjectsAndPrograms School Management System createNotice.php unrestricted uploadProjectsAndPrograms School Management System
CVE-2025-11656ProjectsAndPrograms School Management System editNotes.php unrestricted uploadProjectsAndPrograms School Management System
CVE-2025-11604projectworlds Online Ordering Food System all-orders.php sql injectionprojectworlds Online Ordering Food System
CVE-2025-11557projectworlds Gate Pass Management System add-pass.php sql injectionprojectworlds Gate Pass Management System
CVE-2025-11475projectworlds Advanced Library Management System view_member.php sql injectionprojectworlds Advanced Library Management System
CVE-2025-11426projectworlds Advanced Library Management System edit_book.php unrestricted uploadprojectworlds Advanced Library Management System
CVE-2025-11425projectworlds Advanced Library Management System edit_admin.php cross site scriptingprojectworlds Advanced Library Management System
CVE-2025-11103Projectworlds Online Tours and Travels change-image.php unrestricted uploadProjectworlds Online Tours and Travels
CVE-2025-11070Projectworlds Online Shopping System cart_add.php sql injectionProjectworlds Online Shopping System
CVE-2025-11067Projectworlds Visitor Management System Add Visitor myform.php cross site scriptingProjectworlds Visitor Management System
CVE-2025-11056ProjectsAndPrograms School Management System select-students.php sql injectionProjectsAndPrograms School Management System
CVE-2024-7659projectsend Password Reset Token functions.php generate_random_string random valuesn/a projectsend
CVE-2024-5262ProjectDiscovery Interactsh - Files or Directories Accessible to External PartiesProjectDiscovery Interactsh
CVE-2024-40641Unsigned code template execution through workflows in projectdiscovery/nucleiprojectdiscovery nuclei
CVE-2024-39897Cache driver GetBlob() allows read access to any blob without access control checkproject-zot zot
CVE-2024-39690Capsule tenant owner with "patch namespace" permission can hijack system namespacesprojectcapsule capsule
CVE-2024-27920Unsigned code template execution through workflows in projectdiscovery/nucleiprojectdiscovery nuclei
CVE-2024-11059Project Worlds Free Download Online Shopping System success.php sql injectionProject Worlds Free Download Online Shopping System
CVE-2024-10735Project Worlds Life Insurance Management System editNominee.php sql injectionProject Worlds Life Insurance Management System
CVE-2024-10734Project Worlds Life Insurance Management System editPayment.php sql injectionProject Worlds Life Insurance Management System
CVE-2024-10447Project Worlds Online Time Table Generator staffdashboard.php sql injectionProject Worlds Online Time Table Generator
CVE-2024-10446Project Worlds Online Time Table Generator admindashboard.php sql injectionProject Worlds Online Time Table Generator
CVE-2024-10433Project Worlds Simple Web-Based Chat Application index.php cross site scriptingProject Worlds Simple Web-Based Chat Application
CVE-2024-10432Project Worlds Simple Web-Based Chat Application index.php sql injectionProject Worlds Simple Web-Based Chat Application
CVE-2024-10425Project Worlds Student Project Allocation System Project Selection Page move_up_project.php sql injectionProject Allocation System
CVE-2024-10424Project Worlds Student Project Allocation System Project Selection Page remove_project.php sql injectionProject Allocation System
CVE-2024-10423Project Worlds Student Project Allocation System Project Selection Page project_selection.php sql injectionProject Allocation System
CVE-2024-0783Project Worlds Online Admission System documents.php unrestricted uploadProject Worlds Online Admission System
CVE-2024-0730Project Worlds Online Time Table Generator course_ajax.php sql injectionProject Worlds Online Time Table Generator
CVE-2024-0726Project Worlds Student Project Allocation System Admin Login Module admin_login.php cross site scriptingProject Allocation System
200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.