Visitor Management System
13 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Visitor Management System, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Visitor Management System CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 3 |
| 2025-09 | 1 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 1 |
| 2026-05 | 1 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 13 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High6
- Medium4
- Low1
Latest CVEs
The 13 most recently published vulnerabilities affecting Visitor Management System.
- CVE-2026-10170code-projects Visitor Management System phone_0.php sql injection6.3
- CVE-2026-37748Visitor Management System 1.0 by sanjay1313 is vulnerable to Unrestricted File Upload in vms/php/admin_user_insert.php and vms/php/update_1.php. The move_uploaded_file() function is called without ...7.2
- CVE-2025-11067Projectworlds Visitor Management System Add Visitor myform.php cross site scripting2.4
- CVE-2025-9047projectworlds Visitor Management System visitor_out.php sql injection7.3
- CVE-2025-8948projectworlds Visitor Management System front.php sql injection7.3
- CVE-2025-8947projectworlds Visitor Management System query_data.php sql injection7.3
- CVE-2024-34226SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&id=1 in SourceCodester Visitor Management System 1.0 allow attackers to execute arbitrary SQL commands via the id parameters.9.4
- CVE-2024-22983SQL injection vulnerability in Projectworlds Visitor Management System in PHP v.1.0 allows a remote attacker to escalate privileges via the name parameter in the myform.php endpoint.8.1
- CVE-2024-22922An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to escalate privileges via a crafted script to the login page in the POST/index.php9.8
- CVE-2024-0650Project Worlds Visitor Management System URL dataset.php cross site scripting4.3
- CVE-2023-5918SourceCodester Visitor Management System manage_user.php sql injection6.3
- CVE-2020-25761Projectworlds Visitor Management System in PHP 1.0 allows XSS. The file myform.php does not perform input validation on the request parameters. An attacker can inject javascript payloads in the par...6.1
- CVE-2020-25760Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input validation on the 'rid' parameter. An attacker can append SQL queries to the input...8.8
Product grouping is registry-driven, with AI assist and human review. How it works