Code-Projects Hospital Information System vulnerabilities
7 known vulnerabilities affecting code-projects/hospital_information_system.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM2LOW1
Vulnerabilities
Page 1 of 1
CVE-2026-85399P3HIGHCVSS 7.3v1.02026-09-04
CVE-2026-85399 [HIGH] CWE-74 CVE-2026-85399: A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by th
A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by this vulnerability is the function getSinglePresp of the file includes/presp/PrespController.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and m
nvd
CVE-2026-76574P3HIGHCVSS 7.3v1.02026-08-19
CVE-2026-76574 [HIGH] CWE-74 CVE-2026-76574: A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the
A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the function User::login of the file includes/users/UsersController.php of the component User Login Handler. This manipulation of the argument email causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and ma
nvd
CVE-2026-85398P3HIGHCVSS 7.3v1.02026-09-04
CVE-2026-85398 [HIGH] CWE-74 CVE-2026-85398: A vulnerability was identified in code-projects Hospital Information System 1.0. Affected is the fun
A vulnerability was identified in code-projects Hospital Information System 1.0. Affected is the function viewReq of the file viewReq.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
nvd
CVE-2026-85397P3HIGHCVSS 7.3v1.02026-09-04
CVE-2026-85397 [HIGH] CWE-74 CVE-2026-85397: A vulnerability was determined in code-projects Hospital Information System 1.0. This impacts the fu
A vulnerability was determined in code-projects Hospital Information System 1.0. This impacts the function findBySearch of the file addReq.php. This manipulation of the argument Search causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
nvd
CVE-2026-86302P4MEDIUMCVSS 5.3v1.02026-09-07
CVE-2026-86302 [MEDIUM] CWE-200 CVE-2026-86302: A vulnerability was found in code-projects Hospital Information System 1.0. Affected by this vulnera
A vulnerability was found in code-projects Hospital Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /HIS/his.sql of the component SQL Database Backup File Handler. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possible. The exploit has been made public
nvd
CVE-2026-86301P4LOWCVSS 3.5v1.02026-09-07
CVE-2026-86301 [LOW] CWE-79 CVE-2026-86301: A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unkn
A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. Such manipulation of the argument ID leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may b
nvd
CVE-2023-37070P4MEDIUMCVSS 4.8v1.02023-08-14
CVE-2023-37070 [MEDIUM] CWE-79 CVE-2023-37070: Code Projects Hospital Information System 1.0 is vulnerable to Cross Site Scripting (XSS)
Code Projects Hospital Information System 1.0 is vulnerable to Cross Site Scripting (XSS)
nvd