Travel Management System
20 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Travel Management System, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Travel Management System CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 3 |
| 2024-12 | 3 |
| 2025-01 | 1 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 4 |
| 2025-09 | 5 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 20 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical4
- High10
- Medium6
Latest CVEs
The 15 most recently published vulnerabilities affecting Travel Management System.
- CVE-2025-9928projectworlds Travel Management System viewcategory.php sql injection7.3
- CVE-2025-9927projectworlds Travel Management System viewpackage.php sql injection7.3
- CVE-2025-9926projectworlds Travel Management System viewsubcategory.php sql injection7.3
- CVE-2025-9925projectworlds Travel Management System detail.php sql injection7.3
- CVE-2025-9924projectworlds Travel Management System enquiry.php sql injection7.3
- CVE-2025-9053projectworlds Travel Management System updatesubcategory.php sql injection7.3
- CVE-2025-9052projectworlds Travel Management System updatepackage.php sql injection7.3
- CVE-2025-9051projectworlds Travel Management System updatecategory.php sql injection7.3
- CVE-2025-9050projectworlds Travel Management System addcategory.php sql injection7.3
- CVE-2025-0229code-projects Travel Management System enquiry.php sql injection6.3
- CVE-2024-12950code-projects/projectworlds Travel Management System subcat.php sql injection6.3
- CVE-2024-12949code-projects Travel Management System package.php sql injection6.3
- CVE-2024-12948code-projects Travel Management System detail.php sql injection6.3
- CVE-2024-51328Cross Site Scripting vulnerability in addcategory.php in projectworld's Travel Management System v1.0 allows remote attacker to inject arbitrary code via the t2 parameter.6.1
- CVE-2024-51327SQL Injection in loginform.php in ProjectWorld's Travel Management System v1.0 allows remote attackers to bypass authentication via SQL Injection in the 'username' and 'password' fields.9.8
Product grouping is registry-driven, with AI assist and human review. How it works