VendorsProjectworldsonline_time_table_generatorall versions
Vulnerabilities

Projectworlds Online Time Table Generator

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2025-2661
Project Worlds Online Time Table Generator index.php sql injection
Published 2025-03-23 · Analyzed
9.8EPSS 0.007
CVE-2025-3040
Project Worlds Online Time Table Generator add_student.php unrestricted upload
Published 2025-03-31 · Analyzed
9.8EPSS 0.006
CVE-2024-0730
Project Worlds Online Time Table Generator course_ajax.php sql injection
Published 2024-01-19 · Modified
9.8EPSS 0.006
CVE-2025-2659
Project Worlds Online Time Table Generator index.php sql injection
Published 2025-03-23 · Analyzed
9.8EPSS 0.005
CVE-2025-2660
Project Worlds Online Time Table Generator index.php sql injection
Published 2025-03-23 · Analyzed
9.8EPSS 0.005
CVE-2025-5003
projectworlds Online Time Table Generator semester_ajax.php sql injection
Published 2025-05-20 · Analyzed
9.8EPSS 0.005
CVE-2025-5004
projectworlds Online Time Table Generator add_course.php sql injection
Published 2025-05-20 · Analyzed
9.8EPSS 0.005
CVE-2025-5008
projectworlds Online Time Table Generator add_teacher.php sql injection
Published 2025-05-20 · Analyzed
9.8EPSS 0.005
CVE-2025-3041
Project Worlds Online Time Table Generator updatestudent.php unrestricted upload
Published 2025-03-31 · Analyzed
9.8EPSS 0.005
CVE-2025-3042
Project Worlds Online Time Table Generator updateprofile.php unrestricted upload
Published 2025-04-01 · Analyzed
9.8EPSS 0.005
CVE-2025-70146
Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized administrative operations (e.g.,adding records, deleting records) via direct HTTP requests to affected endpoints without a valid session.
Published 2026-02-18 · Modified
9.1EPSS 0.006
CVE-2025-2662
Project Worlds Online Time Table Generator studentdashboard.php sql injection
Published 2025-03-23 · Analyzed
8.8EPSS 0.006
CVE-2024-10447
Project Worlds Online Time Table Generator staffdashboard.php sql injection
Published 2024-10-28 · Analyzed
8.8EPSS 0.005
CVE-2025-70147
Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to obtain sensitive information (including plaintext password field values) via direct HTTP GET requests to these endpoints without a valid session.
Published 2026-02-18 · Modified
7.5EPSS 0.005
CVE-2024-10446
Project Worlds Online Time Table Generator admindashboard.php sql injection
Published 2024-10-28 · Analyzed
7.2EPSS 0.005