mayurik

275 tracked vulnerabilities.

CVE-2025-8983 HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via expense_for Parameter
Aug 14, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-8982 HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via curr_code Parameter
Aug 14, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-8981 HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via payment_type Parameter
Aug 14, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-8972 HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via Email Parameter in Admin Login Page
Aug 14, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-8971 HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via val-username Parameter
Aug 14, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-8970 HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via Booking ID Parameter
Aug 14, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-8969 HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via /admin/approve_user.php ID Parameter
Aug 14, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-8968 HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via /admin/disapprove_user.php ID Parameter
Aug 14, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-8967 HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via pname Parameter
Aug 14, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-8966 HIGH
Online Tour and Travel Management System 1.0 - SQL Injection via tax.php tname Parameter
Aug 14, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-7144 LOW
Best Salon Management System 1.0 - Cross-Site Scripting via Admin Name Parameter in Admin Profile Page
Jul 07, 2025
CVSS 2.4
EPSS 0.00
CVE-2025-7143 LOW
Best Salon Management System 1.0 - Cross-Site Scripting via Tax Name Parameter in Update Tax Page
Jul 07, 2025
CVSS 2.4
EPSS 0.00
CVE-2025-7142 LOW
Best Salon Management System 1.0 - Cross-Site Scripting in Search Appointment Panel
Jul 07, 2025
CVSS 2.4
EPSS 0.00
CVE-2025-7141 LOW
Best Salon Management System 1.0 - Cross-Site Scripting in Update Staff Page
Jul 07, 2025
CVSS 2.4
EPSS 0.00
CVE-2025-7140 LOW
Best Salon Management System 1.0 - Cross-Site Scripting via Staff Name Parameter in Update Staff Page
Jul 07, 2025
CVSS 2.4
EPSS 0.00
CVE-2025-7139 LOW
Best Salon Management System 1.0 - Cross-Site Scripting via Update Customer Details Page Name Parameter
Jul 07, 2025
CVSS 2.4
EPSS 0.00
CVE-2025-7138 MEDIUM
Best Salon Management System 1.0 - SQL Injection via adminname Parameter
Jul 07, 2025
CVSS 6.3
EPSS 0.00
CVE-2025-7137 MEDIUM
Best Salon Management System 1.0 - SQL Injection via staff_id Parameter
Jul 07, 2025
CVSS 6.3
EPSS 0.00
CVE-2025-6880 MEDIUM
Best Salon Management System 1.0 - SQL Injection via editid Parameter
Jun 30, 2025
CVSS 6.3
EPSS 0.00
CVE-2025-6879 MEDIUM
Best Salon Management System 1.0 - SQL Injection via Name Parameter in /panel/add-tax.php
Jun 30, 2025
CVSS 6.3
EPSS 0.00
CVE-2025-6878 MEDIUM
Best Salon Management System 1.0 - SQL Injection via searchdata Parameter
Jun 30, 2025
CVSS 6.3
EPSS 0.00
CVE-2025-6877 MEDIUM
Best Salon Management System 1.0 - SQL Injection via editid Parameter
Jun 30, 2025
CVSS 6.3
EPSS 0.00
CVE-2025-6876 MEDIUM
Best Salon Management System 1.0 - SQL Injection via Name Parameter in /panel/add-category.php
Jun 29, 2025
CVSS 6.3
EPSS 0.00
CVE-2025-6875 MEDIUM
Best Salon Management System 1.0 - SQL Injection via editid Parameter
Jun 29, 2025
CVSS 6.3
EPSS 0.00
CVE-2025-6874 MEDIUM
Best Salon Management System 1.0 - SQL Injection via user_id/plan_id Parameter
Jun 29, 2025
CVSS 6.3
EPSS 0.00