VendorsOranbyteschool_management_systemall versions
Vulnerabilities

Oranbyte School Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2025-11656
ProjectsAndPrograms School Management System editNotes.php unrestricted upload
Published 2025-10-13 · Analyzed
9.8EPSS 0.006
CVE-2025-11657
ProjectsAndPrograms School Management System createNotice.php unrestricted upload
Published 2025-10-13 · Analyzed
9.8EPSS 0.006
CVE-2025-11659
ProjectsAndPrograms School Management System uploadNotes.php unrestricted upload
Published 2025-10-13 · Analyzed
9.8EPSS 0.006
CVE-2025-11661
ProjectsAndPrograms School Management System missing authentication
Published 2025-10-13 · Analyzed
9.8EPSS 0.005
CVE-2025-11658
ProjectsAndPrograms School Management System changeSllyabus.php unrestricted upload
Published 2025-10-13 · Analyzed
9.8EPSS 0.005
CVE-2025-11660
ProjectsAndPrograms School Management System uploadSllyabus.php unrestricted upload
Published 2025-10-13 · Analyzed
9.8EPSS 0.005
CVE-2025-11056
ProjectsAndPrograms School Management System select-students.php sql injection
Published 2025-09-27 · Analyzed
9.8EPSS 0.004
CVE-2025-51967
A Reflected Cross-site Scripting (XSS) vulnerability exists in the themeSet.php file of ProjectsAndPrograms School Management System 1.0. The application fails to sanitize user-supplied input in the theme POST parameter, allowing an attacker to inject and execute arbitrary JavaScript in a victim's browser.
Published 2025-08-28 · Analyzed
6.1EPSS 0.002