Filtered by vendor Carmelo Subscriptions
Total 49 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-6482 1 Carmelo 1 Simple Pizza Ordering System 2025-06-25 7.3 High
A vulnerability, which was classified as critical, was found in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /edituser-exec.php. The manipulation of the argument userid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-6483 1 Carmelo 1 Simple Pizza Ordering System 2025-06-25 7.3 High
A vulnerability has been found in code-projects Simple Pizza Ordering System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edituser.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-25251 1 Carmelo 1 Agro-school Management System 2025-06-09 8.8 High
code-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control.
CVE-2024-24100 1 Carmelo 1 Computer Book Store 2025-04-10 8.3 High
Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via PublisherID.
CVE-2024-24096 2 Carmelo, Code-projects 2 Computer Book Store, Computer Book Store 2025-04-10 7.8 High
Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via BookSBIN.
CVE-2024-28279 2 Carmelo, Code-projects 2 Computer Book Store, Computer Book Store 2025-04-10 7.3 High
Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via book.php?bookisbn=.
CVE-2024-25250 1 Carmelo 1 Agro-school Management System 2025-04-08 9.8 Critical
SQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code via the Login page.
CVE-2025-25914 1 Carmelo 1 Online Exam Mastering System 2025-04-08 9.8 Critical
SQL injection vulnerability in Online Exam Mastering System v.1.0 allows a remote attacker to execute arbitrary code via the fid parameter
CVE-2024-24105 1 Carmelo 1 Computer Science Time Table System 2025-03-27 7.8 High
SQL Injection vulnerability in Code-projects Computer Science Time Table System 1.0 allows attackers to run arbitrary code via adminFormvalidation.php.