VendorsSenior Walterweb-based_pharmacy_product_management_systemall versions
Vulnerabilities

Senior Walter Web-based pharmacy product management system

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

28CVEs
CVE-2025-3729
SourceCodester Web-based Pharmacy Product Management System Database Backup backup.php os command injection
Published 2025-04-16 · Analyzed
9.8EPSS 0.033
CVE-2025-3783
SourceCodester Web-based Pharmacy Product Management System add-product.php unrestricted upload
Published 2025-04-18 · Analyzed
9.8EPSS 0.010
CVE-2025-3383
SourceCodester Web-based Pharmacy Product Management System search_sales.php sql injection
Published 2025-04-07 · Analyzed
9.8EPSS 0.006
CVE-2025-3694
SourceCodester Web-based Pharmacy Product Management System Login sql injection
Published 2025-04-16 · Analyzed
9.8EPSS 0.006
CVE-2025-3244
SourceCodester Web-based Pharmacy Product Management System Create User Page add-admin.php unrestricted upload
Published 2025-04-04 · Analyzed
8.8EPSS 0.006
CVE-2025-3765
SourceCodester Web-based Pharmacy Product Management System edit-photo.php unrestricted upload
Published 2025-04-17 · Analyzed
8.8EPSS 0.006
CVE-2025-3764
SourceCodester Web-based Pharmacy Product Management System edit-product.php unrestricted upload
Published 2025-04-17 · Analyzed
8.8EPSS 0.006
CVE-2025-3697
SourceCodester Web-based Pharmacy Product Management System edit-product.php sql injection
Published 2025-04-16 · Analyzed
8.8EPSS 0.005
CVE-2025-3696
SourceCodester Web-based Pharmacy Product Management System search_stock. php sql injection
Published 2025-04-16 · Analyzed
8.8EPSS 0.005
CVE-2025-63712
Cross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete-user.php) allows remote attackers to delete arbitrary user accounts via forged cross-origin GET requests because the endpoint relies solely on session cookies and lacks CSRF protection.
Published 2025-11-10 · Modified
8.8EPSS 0.002
CVE-2025-45997
Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can upload a PHP file disguised as an image by modifying the Content-Type header to image/jpg.
Published 2025-05-28 · Analyzed
8.6EPSS 0.005
CVE-2025-56274
SourceCodester Web-based Pharmacy Product Management System 1.0 is vulnerable to Incorrect Access Control, which allows low-privileged users to forge high privileged (such as admin) sessions and perform sensitive operations such as adding new users.
Published 2025-09-15 · Modified
8.1EPSS 0.004
CVE-2026-30575
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file. The application fails to validate the "txtqty" parameter during stock entry, allowing negative values to be processed. This causes the system to decrease the inventory level instead of increasing it, leading to inventory corruption and potential Denial of Service by depleting stock records.
Published 2026-03-27 · Analyzed
7.5EPSS 0.005
CVE-2026-30576
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file. The application fails to validate the "txtprice" and "txttotalcost" parameters during stock entry, allowing negative financial values to be submitted. This leads to corruption of financial records, allowing attackers to manipulate inventory asset values and procurement costs.
Published 2026-03-27 · Analyzed
7.5EPSS 0.004
CVE-2026-30574
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file. The application fails to verify if the requested sales quantity (txtqty) exceeds the available stock level. An attacker can manipulate the request to purchase a quantity that is significantly higher than the actual available stock.
Published 2026-03-27 · Analyzed
7.5EPSS 0.004
CVE-2026-30573
A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is located in the add-sales.php file. The application fails to validate the "txtprice" and "txttotalcost" parameters, allowing attackers to submit negative values for sales transactions. This leads to incorrect financial calculations, corruption of sales reports, and potential financial loss.
Published 2026-04-01 · Analyzed
7.5EPSS 0.004
CVE-2026-3401
SourceCodester Web-based Pharmacy Product Management System session expiration
Published 2026-03-02 · Analyzed
6.6EPSS 0.005
CVE-2025-45751
SourceCodester Web Based Pharmacy Product Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add-admin.php via the Fullname text field.
Published 2025-05-05 · Modified
6.1EPSS 0.003
CVE-2025-56018
SourceCodester Web-based Pharmacy Product Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in Category Management via the category name field.
Published 2025-09-30 · Analyzed
6.1EPSS 0.002
CVE-2025-65215
Sourcecodester Web-based Pharmacy Product Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /product_expiry/add-supplier.php via the Supplier Name field.
Published 2025-12-02 · Analyzed
6.1EPSS 0.002
CVE-2025-3822
SourceCodester Web-based Pharmacy Product Management System changepassword.php cross site scripting
Published 2025-04-20 · Analyzed
5.4EPSS 0.005
CVE-2025-3821
SourceCodester Web-based Pharmacy Product Management System add-admin.php cross site scripting
Published 2025-04-20 · Analyzed
5.4EPSS 0.004
CVE-2026-3766
SourceCodester Web-based Pharmacy Product Management System edit-profile.php cross site scripting
Published 2026-03-08 · Analyzed
5.4EPSS 0.003
CVE-2025-3823
SourceCodester Web-based Pharmacy Product Management System add-stock.php cross site scripting
Published 2025-04-20 · Analyzed
4.8EPSS 0.004
CVE-2025-3826
SourceCodester Web-based Pharmacy Product Management System add-supplier.php cross site scripting
Published 2025-04-20 · Analyzed
4.8EPSS 0.004
CVE-2025-3825
SourceCodester Web-based Pharmacy Product Management System add-category.php cross site scripting
Published 2025-04-20 · Analyzed
4.8EPSS 0.004
CVE-2025-3824
SourceCodester Web-based Pharmacy Product Management System add-product.php cross site scripting
Published 2025-04-20 · Analyzed
4.8EPSS 0.004
CVE-2025-4547
SourceCodester Web-based Pharmacy Product Management System Add User Page cross site scripting
Published 2025-05-11 · Analyzed
4.8EPSS 0.004