VendorsMayuri Kbest_employee_management_systemall versions
Vulnerabilities

Mayuri K Best Employee Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2025-1593
SourceCodester Best Employee Management System Profile Picture unrestricted upload
Published 2025-02-23 · Analyzed
9.8EPSS 0.005
CVE-2025-2046
SourceCodester Best Employee Management System print1.php sql injection
Published 2025-03-06 · Analyzed
9.8EPSS 0.005
CVE-2024-11212
SourceCodester Best Employee Management System fetch_product_details.php sql injection
Published 2024-11-14 · Analyzed
8.8EPSS 0.007
CVE-2025-0802
SourceCodester Best Employee Management System Administrative Endpoint View_user.php access control
Published 2025-01-29 · Analyzed
8.1EPSS 0.006
CVE-2025-1606
SourceCodester Best Employee Management System backups.php information disclosure
Published 2025-02-24 · Analyzed
7.5EPSS 0.007
CVE-2024-11214
SourceCodester Best Employee Management System profile.php unrestricted upload
Published 2024-11-14 · Analyzed
7.2EPSS 0.007
CVE-2024-11213
SourceCodester Best Employee Management System edit_role.php sql injection
Published 2024-11-14 · Analyzed
7.2EPSS 0.005
CVE-2025-1592
SourceCodester Best Employee Management System Add Role Page Role.php cross site scripting
Published 2025-02-23 · Analyzed
6.1EPSS 0.004
CVE-2025-44185
SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/change_pass.php via the password parameter.
Published 2025-05-15 · Analyzed
5.4EPSS 0.002
CVE-2025-44186
SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operation/User.php page.
Published 2025-05-14 · Analyzed
5.4EPSS 0.002
CVE-2025-1607
SourceCodester Best Employee Management System salary_slip.php authorization
Published 2025-02-24 · Analyzed
5.3EPSS 0.006
CVE-2025-44184
SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the website_image, fname, lname, contact, username, and address parameters.
Published 2025-05-14 · Analyzed
4.8EPSS 0.003