VendorsProjectworldstravel_management_system1.0
Vulnerabilities

Projectworlds Project Worlds Travel Management System 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2020-24203
Insecure File Permissions and Arbitrary File Upload in the upload pic function in updatesubcategory.php in Projects World Travel Management System v1.0 allows remote unauthenticated attackers to gain remote code execution.
Published 2020-08-27 · Modified
9.8EPSS 0.037
CVE-2024-51327
SQL Injection in loginform.php in ProjectWorld's Travel Management System v1.0 allows remote attackers to bypass authentication via SQL Injection in the 'username' and 'password' fields.
Published 2024-11-04 · Analyzed
9.8EPSS 0.008
CVE-2025-9053
projectworlds Travel Management System updatesubcategory.php sql injection
Published 2025-08-15 · Analyzed
9.8EPSS 0.005
CVE-2025-9924
projectworlds Travel Management System enquiry.php sql injection
Published 2025-09-03 · Analyzed
9.8EPSS 0.004
CVE-2025-9925
projectworlds Travel Management System detail.php sql injection
Published 2025-09-03 · Analyzed
9.8EPSS 0.004
CVE-2025-9927
projectworlds Travel Management System viewpackage.php sql injection
Published 2025-09-03 · Analyzed
9.8EPSS 0.004
CVE-2025-9926
projectworlds Travel Management System viewsubcategory.php sql injection
Published 2025-09-03 · Analyzed
9.8EPSS 0.004
CVE-2025-9928
projectworlds Travel Management System viewcategory.php sql injection
Published 2025-09-03 · Analyzed
9.8EPSS 0.004
CVE-2025-9050
projectworlds Travel Management System addcategory.php sql injection
Published 2025-08-15 · Analyzed
9.8EPSS 0.004
CVE-2025-9051
projectworlds Travel Management System updatecategory.php sql injection
Published 2025-08-15 · Analyzed
9.8EPSS 0.004
CVE-2025-9052
projectworlds Travel Management System updatepackage.php sql injection
Published 2025-08-15 · Analyzed
9.8EPSS 0.004
CVE-2024-51326
SQL Injection vulnerability in projectworlds Travel management System v.1.0 allows a remote attacker to execute arbitrary code via the 't2' parameter in deletesubcategory.php.
Published 2024-11-04 · Analyzed
7.5EPSS 0.009
CVE-2020-29205
XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via the name field
Published 2021-05-17 · Modified
6.1EPSS 0.015
CVE-2024-51328
Cross Site Scripting vulnerability in addcategory.php in projectworld's Travel Management System v1.0 allows remote attacker to inject arbitrary code via the t2 parameter.
Published 2024-11-04 · Analyzed
6.1EPSS 0.004