CVE Tools

Web-based Pharmacy Product Management System

30 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Web-based Pharmacy Product Management System, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Web-based Pharmacy Product Management System CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Web-based Pharmacy Product Management System CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-0415
2025-053
2025-060
2025-070
2025-080
2025-092
2025-100
2025-111
2025-121
2026-010
2026-020
2026-036
2026-041
2026-051
2026-060
2026-070
2026-080
2026-090

Severity

How the 30 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High1033%
  • Medium1137%
  • Low930%

Latest CVEs

The 15 most recently published vulnerabilities affecting Web-based Pharmacy Product Management System.

  1. CVE-2026-7746SourceCodester Web-based Pharmacy Product Management System edit-admin.php sql injection6.3
  2. CVE-2026-30573A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is located in the add-sales.php file. The application fails to validate the "txtpri...7.5
  3. CVE-2026-30576A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file. The application fails to validate the "txtprice" and "txttotalcost" paramet...7.5
  4. CVE-2026-30575A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file. The application fails to validate the "txtqty" parameter during stock entry...7.5
  5. CVE-2026-30574A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file. The application fails to verify if the requested sales quantity (txtqty) ex...7.5
  6. CVE-2026-4013SourceCodester Web-based Pharmacy Product Management System add_admin.php improper authorization6.3
  7. CVE-2026-3766SourceCodester Web-based Pharmacy Product Management System edit-profile.php cross site scripting3.5
  8. CVE-2026-3401SourceCodester Web-based Pharmacy Product Management System session expiration3.1
  9. CVE-2025-65215Sourcecodester Web-based Pharmacy Product Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /product_expiry/add-supplier.php via the Supplier Name field.6.1
  10. CVE-2025-63712Cross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete-user.php) allows remote attackers to delete arbitrary user accounts via forg...8.8
  11. CVE-2025-56018SourceCodester Web-based Pharmacy Product Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in Category Management via the category name field.6.1
  12. CVE-2025-56274SourceCodester Web-based Pharmacy Product Management System 1.0 is vulnerable to Incorrect Access Control, which allows low-privileged users to forge high privileged (such as admin) sessions and pe...8.1
  13. CVE-2025-45997Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can upload a PHP file disguised as an image by modifying the Content-Type header to im...8.6
  14. CVE-2025-4547SourceCodester Web-based Pharmacy Product Management System Add User Page cross site scripting2.4
  15. CVE-2025-45751SourceCodester Web Based Pharmacy Product Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add-admin.php via the Fullname text field.6.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store