VendorsAhsanriaz26gmailcomsales_and_inventory_system1.0
Vulnerabilities

Ahsanriaz26gmailcom ahsanriaz26@gmail.com Sales And Inventory System 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

31CVEs
CVE-2026-30562
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_stock.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published 2026-03-30 · Analyzed
9.3EPSS 0.003
CVE-2026-3793
SourceCodester Sales and Inventory System GET Parameter sales_invoice1.php sql injection
Published 2026-03-09 · Analyzed
8.8EPSS 0.004
CVE-2026-4779
SourceCodester Sales and Inventory System HTTP GET Parameter update_customer_details.php sql injection
Published 2026-03-24 · Analyzed
8.8EPSS 0.004
CVE-2026-4826
SourceCodester Sales and Inventory System HTTP GET Parameter update_stock.php sql injection
Published 2026-03-25 · Analyzed
8.8EPSS 0.003
CVE-2026-3790
SourceCodester Sales and Inventory System POST Parameter check_supplier_details.php sql injection
Published 2026-03-09 · Analyzed
8.8EPSS 0.003
CVE-2026-3792
SourceCodester Sales and Inventory System GET Parameter purchase_invoice.php sql injection
Published 2026-03-09 · Analyzed
8.8EPSS 0.003
CVE-2026-3756
SourceCodester Sales and Inventory System check_item_details.php sql injection
Published 2026-03-08 · Analyzed
8.8EPSS 0.003
CVE-2026-3755
SourceCodester Sales and Inventory System POST check_customer_details.php sql injection
Published 2026-03-08 · Analyzed
8.8EPSS 0.003
CVE-2026-3754
SourceCodester Sales and Inventory System add_stock.php sql injection
Published 2026-03-08 · Analyzed
8.8EPSS 0.003
CVE-2026-3753
SourceCodester Sales and Inventory System add_sales_print.php sql injection
Published 2026-03-08 · Analyzed
8.8EPSS 0.003
CVE-2026-4781
SourceCodester Sales and Inventory System HTTP GET Parameter update_purchase.php sql injection
Published 2026-03-24 · Analyzed
8.8EPSS 0.003
CVE-2026-4780
SourceCodester Sales and Inventory System HTTP GET Parameter update_out_standing.php sql injection
Published 2026-03-24 · Analyzed
8.8EPSS 0.003
CVE-2026-3791
SourceCodester Sales and Inventory System Search dashboard.php sql injection
Published 2026-03-09 · Analyzed
8.8EPSS 0.003
CVE-2026-4570
SourceCodester Sales and Inventory System HTTP POST Request view_customers.php sql injection
Published 2026-03-23 · Analyzed
8.8EPSS 0.003
CVE-2026-4568
SourceCodester Sales and Inventory System HTTP GET Request update_supplier.php sql injection
Published 2026-03-23 · Modified
6.5EPSS 0.003
CVE-2026-4825
SourceCodester Sales and Inventory System HTTP GET Parameter update_sales.php sql injection
Published 2026-03-25 · Analyzed
6.5EPSS 0.003
CVE-2026-4778
SourceCodester Sales and Inventory System HTTP GET Parameter update_category.php sql injection
Published 2026-03-24 · Analyzed
6.5EPSS 0.003
CVE-2026-4569
SourceCodester Sales and Inventory System HTTP POST Request view_category.php sql injection
Published 2026-03-23 · Analyzed
6.5EPSS 0.003
CVE-2026-4777
SourceCodester Sales and Inventory System POST Parameter view_supplier.php sql injection
Published 2026-03-24 · Analyzed
6.5EPSS 0.002
CVE-2026-4571
SourceCodester Sales and Inventory System HTTP POST Request view_payments.php sql injection
Published 2026-03-23 · Analyzed
6.5EPSS 0.002
CVE-2026-4572
SourceCodester Sales and Inventory System HTTP POST Request view_product.php sql injection
Published 2026-03-23 · Analyzed
6.5EPSS 0.002
CVE-2026-30559
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_sales.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published 2026-03-30 · Modified
6.1EPSS 0.003
CVE-2026-30557
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_category.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published 2026-03-30 · Modified
6.1EPSS 0.003
CVE-2026-30558
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_customer.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published 2026-03-30 · Modified
6.1EPSS 0.003
CVE-2026-30560
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_supplier.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published 2026-03-30 · Modified
6.1EPSS 0.003
CVE-2026-30556
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the index.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published 2026-03-30 · Analyzed
6.1EPSS 0.003
CVE-2026-30561
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the add_purchase.php file via the "msg" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published 2026-03-30 · Modified
6.1EPSS 0.003
CVE-2026-30565
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_supplier.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published 2026-03-30 · Analyzed
6.1EPSS 0.002
CVE-2026-30566
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_customers.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published 2026-03-30 · Analyzed
6.1EPSS 0.002
CVE-2026-30564
A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_payments.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published 2026-03-30 · Analyzed
6.1EPSS 0.002
CVE-2026-30563
A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the update_details.php file. The application fails to sanitize the "website" parameter provided in a POST request. This allows authenticated attackers to inject arbitrary web script or HTML that is stored in the database and executed whenever the store details page is accessed.
Published 2026-03-30 · Analyzed
6.1EPSS 0.002