Construction Management System
14 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Construction Management System, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Construction Management System CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 2 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 12 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 14 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High5
- Medium9
Latest CVEs
The 14 most recently published vulnerabilities affecting Construction Management System.
- CVE-2026-7075itsourcecode Construction Management System locations.php sql injection7.3
- CVE-2026-7074itsourcecode Construction Management System execute1.php sql injection7.3
- CVE-2026-7073itsourcecode Construction Management System execute.php sql injection7.3
- CVE-2026-6191itsourcecode Construction Management System equipments.php sql injection6.3
- CVE-2026-6190itsourcecode Construction Management System employees.php sql injection6.3
- CVE-2026-6030itsourcecode Construction Management System del1.php sql injection6.3
- CVE-2026-6007itsourcecode Construction Management System del.php sql injection6.3
- CVE-2026-5823itsourcecode Construction Management System borrowed_tool_report.php sql injection6.3
- CVE-2026-5719itsourcecode Construction Management System borrowedtool.php sql injection6.3
- CVE-2026-5675itsourcecode Construction Management System Parameter borrowed_tool.php sql injection6.3
- CVE-2026-5660itsourcecode Construction Management System Parameter borrowed_equip.php sql injection6.3
- CVE-2026-5620itsourcecode Construction Management System Parameter borrowed_equip_report.php sql injection6.3
- CVE-2024-50971A SQL injection vulnerability in print.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the map_id parameter.7.2
- CVE-2024-50972A SQL injection vulnerability in printtool.php of Itsourcecode Construction Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the borrow_id parameter.7.2
Product grouping is registry-driven, with AI assist and human review. How it works