Sourcecodester Hospitals Patient Records Management System vulnerabilities
8 known vulnerabilities affecting sourcecodester/hospitals_patient_records_management_system.
Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM1LOW2
Vulnerabilities
Page 1 of 1
CVE-2026-10184P3HIGHCVSS 7.3v1.02026-05-31
CVE-2026-10184 [HIGH] CWE-74 CVE-2026-10184: A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.
A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This impacts an unknown function of the file /classes/Users.php?f=delete. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
nvd
CVE-2026-10185P3HIGHCVSS 7.3v1.02026-05-31
CVE-2026-10185 [HIGH] CWE-74 CVE-2026-10185: A weakness has been identified in SourceCodester Hospitals Patient Records Management System 1.0. Af
A weakness has been identified in SourceCodester Hospitals Patient Records Management System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks
nvd
CVE-2026-11501P3HIGHCVSS 7.3v1.02026-06-08
CVE-2026-11501 [HIGH] CWE-74 CVE-2026-11501: A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.
A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This issue affects some unknown processing of the file /classes/Master.php?f=save_patient. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may
nvd
CVE-2026-9355P3HIGHCVSS 7.3v1.02026-05-24
CVE-2026-9355 [HIGH] CWE-74 CVE-2026-9355: A flaw has been found in SourceCodester Hospitals Patient Records Management System 1.0. The impacte
A flaw has been found in SourceCodester Hospitals Patient Records Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_patient_history. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
cvelistv5nvd
CVE-2026-9356P3HIGHCVSS 7.3v1.02026-05-24
CVE-2026-9356 [HIGH] CWE-74 CVE-2026-9356: A vulnerability has been found in SourceCodester Hospitals Patient Records Management System 1.0. Th
A vulnerability has been found in SourceCodester Hospitals Patient Records Management System 1.0. This affects an unknown function of the file /admin/patients/manage_history.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
cvelistv5nvd
CVE-2026-9342P3MEDIUMCVSS 6.3v1.02026-05-23
CVE-2026-9342 [MEDIUM] CWE-74 CVE-2026-9342: A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.
A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. Impacted is an unknown function of the file /admin/patients/view_history.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
cvelistv5nvd
CVE-2026-11468P4LOWCVSS 2.4v1.02026-06-08
CVE-2026-11468 [LOW] CWE-79 CVE-2026-11468: A vulnerability was detected in SourceCodester Hospitals Patient Records Management System 1.0. This
A vulnerability was detected in SourceCodester Hospitals Patient Records Management System 1.0. This issue affects some unknown processing of the file /admin/?page=room_types. Performing a manipulation of the argument room results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.
nvd
CVE-2026-9564P4LOWCVSS 2.4v1.02026-05-26
CVE-2026-9564 [LOW] CWE-79 CVE-2026-9564: A vulnerability was found in SourceCodester/oretnom23 Hospitals Patient Records Management System 1.
A vulnerability was found in SourceCodester/oretnom23 Hospitals Patient Records Management System 1.0. The impacted element is an unknown function of the file /admin/?page=patients/view_patient. Performing a manipulation of the argument Remarks results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public
nvd