Lost and Found Information System
27 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Lost and Found Information System, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Lost and Found Information System CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 27 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical3
- High3
- Medium18
- Low3
Latest CVEs
The 15 most recently published vulnerabilities affecting Lost and Found Information System.
- CVE-2024-37859Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the page parameter to php-lfis/admin/index.php.6.1
- CVE-2024-37856Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the first, last, middle name fields in the User Profile page.5.4
- CVE-2024-37858SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the id parameter to php-lfis/admin/categories/manage_category.php.9.8
- CVE-2024-37857SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via id parameter to php-lfis/admin/categories/view_category.php.8.8
- CVE-2023-33676Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*" which can be escalated to the remote command execution.8.4
- CVE-2023-33677Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*".7.5
- CVE-2023-38965Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.9.8
- CVE-2023-5018SourceCodester Lost and Found Information System POST Parameter sql injection6.3
- CVE-2023-36159Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers to run arbitrary code via the First Name, Middle Name and Last Name fields o...6.1
- CVE-2023-3850SourceCodester Lost and Found Information System HTTP POST Request sql injection6.3
- CVE-2023-3680SourceCodester Lost and Found Information System HTTP POST Request sql injection6.3
- CVE-2023-3679SourceCodester Lost and Found Information System HTTP POST Request sql injection6.3
- CVE-2023-33592Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information.9.8
- CVE-2023-3177SourceCodester Lost and Found Information System view_inquiry.php sql injection6.3
- CVE-2023-3176SourceCodester Lost and Found Information System manage_user.php sql injection6.3
Product grouping is registry-driven, with AI assist and human review. How it works