Code-Projects Daily Expense Manager vulnerabilities
5 known vulnerabilities affecting code-projects/daily_expense_manager.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2025-40731P3CRITICALCVSS 9.8v1.02025-06-30
CVE-2025-40731 [CRITICAL] CWE-89 CVE-2025-40731: SQL injection vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to
SQL injection vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to retrieve, create, update and delete databases through the pname, pprice and id parameters in /update.php.
nvd
CVE-2025-40732P3HIGHCVSS 7.5v1.02025-06-30
CVE-2025-40732 [HIGH] CWE-203 CVE-2025-40732: user enumeration vulnerability in Daily Expense Manager v1.0. To exploit this vulnerability a POST r
user enumeration vulnerability in Daily Expense Manager v1.0. To exploit this vulnerability a POST request must be sent using the name parameter in /check.php
nvd
CVE-2026-86179P4MEDIUMCVSS 5.3v1.02026-09-06
CVE-2026-86179 [MEDIUM] CWE-200 CVE-2026-86179: A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of
A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Backup Handler. Executing a manipulation can lead to information disclosure. It is possible to launch the attack remotely. The exploit has been published and may be used.
nvd
CVE-2025-40734P4MEDIUMCVSS 6.1v1.02025-06-30
CVE-2025-40734 [MEDIUM] CWE-79 CVE-2025-40734: Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability
Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through the password and confirm_password parameters in /register.php.
nvd
CVE-2025-40733P4MEDIUMCVSS 6.1v1.02025-06-30
CVE-2025-40733 [MEDIUM] CWE-79 CVE-2025-40733: Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability
Reflected Cross-Site Scripting (XSS) vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to execute JavaScript code by sending a POST request through the username parameter in /login.php.
nvd