code-projects has 23 CVEs on record. Disclosure cadence is accelerating: 23 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 23. The median CVSS is 5.3 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-74 (12) and CWE-89 (12). Most affected products: Assessment Management (3), Hospital Information System (3), Internship Management System (3).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 23 prev 0
Products
- Assessment Management 3
- Hospital Information System 3
- Internship Management System 3
- Hotel and Tourism Reservation in PHP 2
- Matrimonial System 2
- Student Crud Operation 2
Worst active — by depth score
CVE-2026-92926High· 7.3A vulnerability has been found in code-projects Matrimonial System 1.052CVE-2026-92366High· 7.3A vulnerability was determined in code-projects Matrimonial System 1.052CVE-2026-86180High· 7.3A vulnerability has been found in code-projects Task Management System In PHP 1.052CVE-2026-86168High· 7.3A security flaw has been discovered in code-projects Content Management System 1.052CVE-2026-85516High· 7.3code-projects Vehicle Management System busprofile.php sql injection52
code-projects vulnerabilities
CVEs affecting code-projects, newest first. Open any entry for full detail, references, and exploit status.
23 CVEsRSS
CVE-2026-93980High· 7.3A weakness has been identified in code-projects Internship Management System 1.0
A weakness has been identified in code-projects Internship Management System 1.0. This vulnerability affects unknown code of the file /admin/login.php of the component Admin Login Form. Executing a manipulation of the argument Password c…
CVE-2026-93979High· 7.3A security flaw has been discovered in code-projects Internship Management System 1.0
A security flaw has been discovered in code-projects Internship Management System 1.0. This affects an unknown part of the file /employer/login.php. Performing a manipulation of the argument Password results in sql injection. The attack …
CVE-2026-93978High· 7.3A vulnerability was identified in code-projects Internship Management System 1.0
A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Such manipulation of the argument Password leads to sql injection. The attack …
CVE-2026-93977Low· 3.5A vulnerability was determined in code-projects Assessment Management 1.0
A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this vulnerability is an unknown functionality of the file lecturer/add-single-mark.php. This manipulation of the argument mark causes cross site scri…
CVE-2026-93976Low· 2.4A vulnerability was found in code-projects Assessment Management 1.0
A vulnerability was found in code-projects Assessment Management 1.0. Affected is an unknown function of the file admin/add-user.php. The manipulation of the argument level results in cross site scripting. The attack may be launched remo…
CVE-2026-93975Low· 2.4A vulnerability has been found in code-projects Assessment Management 1.0
A vulnerability has been found in code-projects Assessment Management 1.0. This impacts an unknown function of the file admin/edit-user.php of the component User Editing. The manipulation of the argument name/sname/email/username/passwor…
CVE-2026-92926High· 7.3PoCA vulnerability has been found in code-projects Matrimonial System 1.0
A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preference.php. Such manipulation of the argument education leads to sql injection. Th…
CVE-2026-92366High· 7.3PoCA vulnerability was determined in code-projects Matrimonial System 1.0
A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search.php of the component Regular Search. This manipulation of the argument sex/mothertongue/maritialstatus/country/state…
CVE-2026-91854Medium· 4.3A vulnerability was identified in code-projects Record Management System 1.0
A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the file main/reg.php. Such manipulation of the argument desc leads to cross site scripting. The attack may be launched remo…
CVE-2026-86519Medium· 5.3PoCA vulnerability was found in code-projects Student Crud Operation 1.0
A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handler. The manipulation results in information disclosure. The attack…
CVE-2026-86518Medium· 6.3PoCA vulnerability has been found in code-projects Student Crud Operation 1.0
A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exp…
CVE-2026-86302Medium· 5.3PoCA vulnerability was found in code-projects Hospital Information System 1.0
A vulnerability was found in code-projects Hospital Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /HIS/his.sql of the component SQL Database Backup File Handler. Performing a manipulation …
CVE-2026-86301Low· 3.5PoCA vulnerability has been found in code-projects Hospital Information System 1.0
A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. Such manipulation of the argument ID lead…
CVE-2026-86217Medium· 5.3PoCA vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0
A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation results in information …
CVE-2026-86216Medium· 4.3PoCA security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0
A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an unknown function of the file /ht/details.php. The manipulation of the argument room leads to cross site scripting. The …
CVE-2026-86181Low· 3.5PoCA vulnerability was found in code-projects Task Management System 1.0
A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the component User Profile Update. The manipulation of the argument ln…
CVE-2026-86180High· 7.3PoCA vulnerability has been found in code-projects Task Management System In PHP 1.0
A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The manipulation of the argument email leads to …
CVE-2026-86179Medium· 5.3PoCA flaw has been found in code-projects Daily Expense Manager 1.0
A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup Handler. Executing a manipulation can lead to information di…
CVE-2026-86168High· 7.3PoCA security flaw has been discovered in code-projects Content Management System 1.0
A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument user_name results in sql injection. The attack can b…
CVE-2026-85516High· 7.3PoCcode-projects Vehicle Management System busprofile.php sql injection
A vulnerability was detected in code-projects Vehicle Management System 1.0. The affected element is an unknown function of the file /busprofile.php. Performing a manipulation of the argument busid results in sql injection. It is possibl…
CVE-2026-85402High· 7.3PoCcode-projects Doctor Appointment System booking.php sql injection
A vulnerability was detected in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient/booking.php. The manipulation of the argument doc_id results in sql injection. The attack may be la…
CVE-2026-85643Medium· 4.7PoCA flaw has been found in code-projects Online Shopping System 1.0
A flaw has been found in code-projects Online Shopping System 1.0. Impacted is the function mysqli_query of the file admin/adduser.php. Executing a manipulation of the argument mobile can lead to sql injection. The attack may be performe…
CVE-2026-85399High· 7.3PoCA security flaw has been discovered in code-projects Hospital Information System 1.0
A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by this vulnerability is the function getSinglePresp of the file includes/presp/PrespController.php. Performing a manipulation of the argument…