Sourcecodester Online Polling System vulnerabilities
6 known vulnerabilities affecting sourcecodester/online_polling_system.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-10082P3CRITICALCVSS 9.8v1.02025-09-08
CVE-2025-10082 [CRITICAL] CWE-74 CVE-2025-10082: A vulnerability has been found in SourceCodester Online Polling System 1.0. Affected is an unknown f
A vulnerability has been found in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/manage-admins.php. Such manipulation of the argument email leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-10076P3CRITICALCVSS 9.8v1.02025-09-08
CVE-2025-10076 [CRITICAL] CWE-74 CVE-2025-10076: A weakness has been identified in SourceCodester Online Polling System 1.0. This affects an unknown
A weakness has been identified in SourceCodester Online Polling System 1.0. This affects an unknown function of the file /manage-profile.php. This manipulation of the argument email causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.
nvd
CVE-2025-10617P3HIGHCVSS 8.8v1.02025-09-17
CVE-2025-10617 [HIGH] CWE-74 CVE-2025-10617: A weakness has been identified in SourceCodester Online Polling System 1.0. Affected by this vulnera
A weakness has been identified in SourceCodester Online Polling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/positions.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.
nvd
CVE-2025-10077P3CRITICALCVSS 9.8v1.02025-09-08
CVE-2025-10077 [CRITICAL] CWE-74 CVE-2025-10077: A security vulnerability has been detected in SourceCodester Online Polling System 1.0. This impacts
A security vulnerability has been detected in SourceCodester Online Polling System 1.0. This impacts an unknown function of the file /registeracc.php. Such manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
nvd
CVE-2025-10078P3CRITICALCVSS 9.8v1.02025-09-08
CVE-2025-10078 [CRITICAL] CWE-74 CVE-2025-10078: A vulnerability was detected in SourceCodester Online Polling System 1.0. Affected is an unknown fun
A vulnerability was detected in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /admin/candidates.php. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.
nvd
CVE-2025-10075P4MEDIUMCVSS 5.4v1.02025-09-08
CVE-2025-10075 [MEDIUM] CWE-79 CVE-2025-10075: A security flaw has been discovered in SourceCodester Online Polling System 1.0. The impacted elemen
A security flaw has been discovered in SourceCodester Online Polling System 1.0. The impacted element is an unknown function of the file /manage-profile.php. The manipulation of the argument firstname results in cross site scripting. The attack can be launched remotely. The exploit has been released to the public and may be exploited.
nvd