VendorsQDOCSsmart_schoolall versions
Vulnerabilities

QDOCS Smart School

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2023-5495
QDocs Smart School HTTP POST Request sql injection
Published 2023-10-10 · Modified
9.8EPSS 0.011
CVE-2024-8784
QDocs Smart School Management System Chat mynewuser sql injection
Published 2024-09-13 · Analyzed
8.8EPSS 0.005
CVE-2025-60500
QDocs Smart School Management System 7.1 allows authenticated users with roles such as "accountant" or "admin" to bypass file type restrictions in the media upload feature by abusing the alternate YouTube URL option. This logic flaw permits uploading of arbitrary PHP files, which are stored in a web-accessible directory.
Published 2025-10-21 · Analyzed
7.2EPSS 0.005
CVE-2024-34240
QDOCS Smart School 7.0.0 is vulnerable to Cross Site Scripting (XSS) resulting in arbitrary code execution in admin functions related to adding or updating records.
Published 2024-05-21 · Analyzed
6.1EPSS 0.004
CVE-2025-41107
Stored XSS in Smart School
Published 2025-11-10 · Analyzed
5.4EPSS 0.002