CVE Tools

Visitor Management System

13 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Visitor Management System, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Visitor Management System CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Visitor Management System CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-083
2025-091
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-041
2026-051
2026-060
2026-070
2026-080
2026-090

Severity

How the 13 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical215%
  • High646%
  • Medium431%
  • Low18%

Latest CVEs

The 13 most recently published vulnerabilities affecting Visitor Management System.

  1. CVE-2026-10170code-projects Visitor Management System phone_0.php sql injection6.3
  2. CVE-2026-37748Visitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File Upload in vms/php/admin_user_insert.php and vms/php/update_1.php. The move_uploaded_file() function is called without ...7.2
  3. CVE-2025-11067Projectworlds Visitor Management System Add Visitor myform.php cross site scripting2.4
  4. CVE-2025-9047projectworlds Visitor Management System visitor_out.php sql injection7.3
  5. CVE-2025-8948projectworlds Visitor Management System front.php sql injection7.3
  6. CVE-2025-8947projectworlds Visitor Management System query_data.php sql injection7.3
  7. CVE-2024-34226SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&id=1 in SourceCodester Visitor Management System 1.0 allow attackers to execute arbitrary SQL commands via the id parameters.9.4
  8. CVE-2024-22983SQL injection vulnerability in Projectworlds Visitor Management System in PHP v.1.0 allows a remote attacker to escalate privileges via the name parameter in the myform.php endpoint.8.1
  9. CVE-2024-22922An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page in the POST/index.php9.8
  10. CVE-2024-0650Project Worlds Visitor Management System URL dataset.php cross site scripting4.3
  11. CVE-2023-5918SourceCodester Visitor Management System manage_user.php sql injection6.3
  12. CVE-2020-25761Projectworlds Visitor Management System in PHP 1.0 allows XSS. The file myform.php does not perform input validation on the request parameters. An attacker can inject javascript payloads in the par...6.1
  13. CVE-2020-25760Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input validation on the 'rid' parameter. An attacker can append SQL queries to the input...8.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store