Products: 2
    Vulnerabilities: 18
    Known Exploited: 0
    4
    Critical Level Threats
    5
    High Level Threats
    9
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-51567

    A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the rname, rcollage, rnumber, rgender and rpassword parameters in a POST HTTP request.

    Last Modified: Jan 16, 2026
    Published: Jan 12, 2026

    CVE-2024-42769

    A Reflected Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php " of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "user_fname" and "user_lname" parameters.

    Last Modified: Apr 30, 2025
    Published: Aug 22, 2024

    CVE-2024-42776

    Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.

    Last Modified: Apr 30, 2025
    Published: Aug 22, 2024

    CVE-2024-42767

    Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.

    Last Modified: Apr 30, 2025
    Published: Aug 22, 2024

    CVE-2024-42768

    A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_room.php.

    Last Modified: Apr 30, 2025
    Published: Aug 22, 2024
    Items Per Page