CVE-2025-13574Medium· 4.7▾ SunlitA weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd of the file /administrator/addcategory.php. This manipulation of the argument catimage causes unrestricted upload. The…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd of the file /administrator/addcategory.php. This manipulation of the argument catimage causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be exploited.
online_bidding_system = 1.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-12378High· 7.3A security flaw has been discovered in code-projects Simple Food Ordering System 1.0
CVE-2025-12301High· 7.3A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0
CVE-2025-14641Medium· 4.7A flaw has been found in code-projects Computer Laboratory System 1.0
CVE-2025-14642Medium· 4.7A vulnerability has been found in code-projects Computer Laboratory System 1.0
CVE-2025-11657High· 7.3A security vulnerability has been detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59
CVE-2025-11658High· 7.3A vulnerability was detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59