Bus Pass Management System
9 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Bus Pass Management System, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Bus Pass Management System CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 1 |
| 2025-05 | 0 |
| 2025-06 | 1 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 9 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High2
- Medium4
- Low1
Latest CVEs
The 9 most recently published vulnerabilities affecting Bus Pass Management System.
- CVE-2025-6288PHPGurukul Bus Pass Management System Profile Page admin-profile.php cross site scripting2.4
- CVE-2025-3146PHPGurukul Bus Pass Management System view-pass-detail.php sql injection7.3
- CVE-2024-44798phpgurukul Bus Pass Management System 1.0 is vulnerable to Cross-site scripting (XSS) in /admin/pass-bwdates-reports-details.php via fromdate and todate parameters.4.8
- CVE-2022-35155Bus Pass Management System v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the searchdata parameter.6.1
- CVE-2022-35156Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..9.8
- CVE-2022-36198Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin/pass-bwdates-reports-details.php, buspassms/admin/changeimage.php, buspassms...9.8
- CVE-2022-29008An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensitive information.6.5
- CVE-2021-44317In Bus Pass Management System v1.0, parameters 'pagedes' and `About Us` are affected with a Stored Cross-site scripting vulnerability.5.4
- CVE-2021-44315In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive files of the application, for example: Any file which cont...7.5
Product grouping is registry-driven, with AI assist and human review. How it works