#PHP,webapps,
-
Dental Clinic Appointment Reservation System 1.0 - Cross Site Request Forgery (Add Admin)
-
Billing Management System 2.0 - Union based SQL injection (Authenticated)
-
Simple Chatbot Application 1.0 - 'Category' Stored Cross site Scripting
-
Advanced Guestbook 2.4.4 - 'Smilies' Persistent Cross-Site Scripting (XSS)
-
Printable Staff ID Card Creator System 1.0 - 'email' SQL Injection
-
EgavilanMedia PHPCRUD 1.0 - 'First Name' SQL Injection
-
COVID19 Testing Management System 1.0 - SQL Injection (Auth Bypass)
-
COVID19 Testing Management System 1.0 - 'Admin name' Cross-Site Scripting (XSS)
-
WordPress Plugin WP Statistics 13.0.7 - Time-Based Blind SQL Injection (Unauthenticated)
-
WordPress Plugin Cookie Law Bar 1.2.1 - 'clb_bar_msg' Stored Cross-Site Scripting (XSS)
-
Gadget Works Online Ordering System 1.0 - 'Category' Persistent Cross-Site Scripting (XSS)
-
ProjeQtOr Project Management 9.1.4 - Remote Code Execution
-
WordPress Plugin WP Prayer version 1.6.1 - 'prayer_messages' Stored Cross-Site Scripting (XSS) (Authenticated)
-
PHP 8.1.0-dev - 'User-Agentt' Remote Code Execution
-
WordPress Plugin Smart Slider-3 3.5.0.8 - 'name' Stored Cross-Site Scripting (XSS)
-
OpenCart 3.0.3.7 - 'Change Password' Cross-Site Request Forgery (CSRF)
-
WordPress Plugin visitors-app 0.3 - 'user-agent' Stored Cross-Site Scripting (XSS)
-
OpenCart 3.0.3.6 - 'subject' Stored Cross-Site Scripting
-
GravCMS 1.10.7 - Arbitrary YAML Write/Update (Unauthenticated) (2)
-
Student Result Management System 1.0 - 'class' SQL Injection