VendorsProjectworldsvisitor_management_systemall versions
Vulnerabilities

Projectworlds Visitor Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2024-22922
An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page in the POST/index.php
Published 2024-01-25 · Modified
9.8EPSS 0.008
CVE-2025-9047
projectworlds Visitor Management System visitor_out.php sql injection
Published 2025-08-15 · Analyzed
9.8EPSS 0.004
CVE-2025-8948
projectworlds Visitor Management System front.php sql injection
Published 2025-08-14 · Analyzed
9.8EPSS 0.004
CVE-2025-8947
projectworlds Visitor Management System query_data.php sql injection
Published 2025-08-14 · Analyzed
9.8EPSS 0.004
CVE-2020-25760
Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input validation on the 'rid' parameter. An attacker can append SQL queries to the input to extract sensitive information from the database.
Published 2020-09-29 · Modified
8.8EPSS 0.022
CVE-2024-22983
SQL injection vulnerability in Projectworlds Visitor Management System in PHP v.1.0 allows a remote attacker to escalate privileges via the name parameter in the myform.php endpoint.
Published 2024-02-28 · Modified
8.1EPSS 0.008
CVE-2020-25761
Projectworlds Visitor Management System in PHP 1.0 allows XSS. The file myform.php does not perform input validation on the request parameters. An attacker can inject javascript payloads in the parameters to perform various attacks such as stealing of cookies,sensitive information etc.
Published 2020-09-29 · Modified
6.1EPSS 0.018
CVE-2024-0650
Project Worlds Visitor Management System URL dataset.php cross site scripting
Published 2024-01-17 · Analyzed
6.1EPSS 0.007
CVE-2025-11067
Projectworlds Visitor Management System Add Visitor myform.php cross site scripting
Published 2025-09-27 · Analyzed
4.8EPSS 0.003