VendorsInventory Management System Projectinventory_management_system1.0
Vulnerabilities

Inventory Management System Project Inventory Management System 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2023-4436
SourceCodester Inventory Management System edit_update.php sql injection
Published 2023-08-20 · Modified
9.8EPSS 0.007
CVE-2023-4558
SourceCodester Inventory Management System staff_data.php sql injection
Published 2023-08-27 · Modified
9.8EPSS 0.007
CVE-2023-4437
SourceCodester Inventory Management System search_sell_paymen_report.php sql injection
Published 2023-08-20 · Modified
9.8EPSS 0.007
CVE-2023-4438
SourceCodester Inventory Management System search_sales_report.php sql injection
Published 2023-08-20 · Modified
9.8EPSS 0.007
CVE-2023-4182
SourceCodester Inventory Management System edit_sell.php sql injection
Published 2023-08-06 · Modified
9.8EPSS 0.006
CVE-2023-4184
SourceCodester Inventory Management System sell_return.php sql injection
Published 2023-08-06 · Modified
9.8EPSS 0.006
CVE-2023-4557
SourceCodester Inventory Management System search_purchase_paymen_report.php sql injection
Published 2023-08-27 · Modified
9.8EPSS 0.006
CVE-2023-4183
SourceCodester Inventory Management System Password edit_update.php access control
Published 2023-08-06 · Modified
9.8EPSS 0.005
CVE-2023-4449
SourceCodester Free and Open Source Inventory Management System sql injection
Published 2023-08-21 · Modified
8.8EPSS 0.008
CVE-2023-4555
SourceCodester Inventory Management System suppliar_data.php cross site scripting
Published 2023-08-27 · Modified
6.1EPSS 0.005
CVE-2023-36337
A reflected cross-site scripting (XSS) vulnerability in the component /index.php/cuzh4 of PHP Inventory Management System 1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Published 2025-12-15 · Analyzed
6.1EPSS 0.002
CVE-2023-36338
Inventory Management System 1 was discovered to contain a SQL injection vulnerability.
Published 2025-12-15 · Analyzed
5.3EPSS 0.004
CVE-2023-24231
A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/categories.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Categories Name parameter.
Published 2023-02-10 · Modified
4.8EPSS 0.005
CVE-2023-24232
A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/product.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Name parameter.
Published 2023-02-10 · Modified
4.8EPSS 0.005
CVE-2023-24233
A stored cross-site scripting (XSS) vulnerability in the component /php-inventory-management-system/orders.php?o=add of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Client Name parameter.
Published 2023-02-10 · Modified
4.8EPSS 0.005
CVE-2023-24234
A stored cross-site scripting (XSS) vulnerability in the component php-inventory-management-system/brand.php of Inventory Management System v1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Brand Name parameter.
Published 2023-02-10 · Modified
4.8EPSS 0.005