Home/Product/jayesh hotel management system
Product

jayesh hotel management system

38 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-63949
all versions
A Reflected Cross-Site Scripting (XSS) vulnerability in yohanawi Hotel Management System (commit 87e004a) allows a remote attacker
6.1MEDIUM
CVE-2025-4500
all versions
A vulnerability, which was classified as critical, has been found in code-projects Hotel Management System 1.0. Affected by this i
5.3MEDIUM
CVE-2024-12186
all versions
A vulnerability was found in code-projects Hotel Management System 1.0 and classified as problematic. This issue affects some unkn
5.3MEDIUM
CVE-2024-12185
all versions
A vulnerability has been found in code-projects Hotel Management System 1.0 and classified as problematic. This vulnerability affe
5.3MEDIUM
CVE-2024-42773
all versions
An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0,
9.1CRITICAL
CVE-2024-42767
all versions
Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.
7.2HIGH
CVE-2024-42776
all versions
Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.
7.2HIGH
CVE-2024-42775
all versions
An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, w
9.1CRITICAL
CVE-2024-42774
all versions
An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which all
7.5HIGH
CVE-2024-42772
all versions
An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an
7.5HIGH
CVE-2024-42768
all versions
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Hotel Management System v1.0 via /admin/delete_room.php.
6.8MEDIUM
CVE-2024-42771
all versions
A Stored Cross Site Scripting (XSS) vulnerability was found in " /admin/edit_room_controller.php" of the Kashipara Hotel Managemen
4.8MEDIUM
CVE-2024-42770
all versions
A Stored Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php" of Kashipara Hotel Management System v1.0,
4.7MEDIUM
CVE-2024-42769
all versions
A Reflected Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php " of Kashipara Hotel Management System v1
6.1MEDIUM
CVE-2024-42558
<= 2020-06-10
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_
9.8CRITICAL
CVE-2024-42557
<= 2020-06-10
A Cross-Site Request Forgery (CSRF) in the component admin_modify_room.php of Hotel Management System commit 91caab8 allows attack
8.8HIGH
CVE-2024-42556
<= 2020-06-10
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admi
9.8CRITICAL
CVE-2024-42555
<= 2020-06-10
A Cross-Site Request Forgery (CSRF) in the component admin_room_removed.php of Hotel Management System commit 91caab8 allows attac
8.8HIGH
CVE-2024-42554
<= 2020-06-10
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the room_type parameter at admi
8.8HIGH
CVE-2024-42553
<= 2020-06-10
A Cross-Site Request Forgery (CSRF) in the component admin_room_added.php of Hotel Management System commit 91caab8 allows attacke
8.8HIGH
CVE-2024-42552
<= 2020-06-10
Hotel Management System commit 91caab8 was discovered to contain a SQL injection vulnerability via the book_id parameter at admin_
8.6HIGH
CVE-2024-25318
all versions
Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'pid' parameter in Hotel/admin/print.php?pid=2.
8.8HIGH
CVE-2024-25316
all versions
Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?eid=2.
9.8CRITICAL
CVE-2024-25315
all versions
Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2.
9.8CRITICAL
CVE-2024-25314
all versions
Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'sid' parameter in Hotel/admin/show.php?sid=2.
9.8CRITICAL
CVE-2023-49272
all versions
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'children' param
5.4MEDIUM
CVE-2023-49271
all versions
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_out_date'
5.4MEDIUM
CVE-2023-49270
all versions
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'check_in_date'
5.4MEDIUM
CVE-2023-49269
all versions
Hotel Management v1.0 is vulnerable to multiple authenticated Reflected Cross-Site Scripting vulnerabilities. The 'adults' paramet
5.4MEDIUM
CVE-2023-3616
< 2.0
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mava Software Hotel Manageme
9.8CRITICAL
CVE-2022-48091
all versions
Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to Cross Site Scripting (XSS) via process_update_profile.php.
5.4MEDIUM
CVE-2022-48090
all versions
Tramyardg hotel-mgmt-system version 2022.4 is vulnerable to SQL Injection via /app/dao/CustomerDAO.php.
6.5MEDIUM
CVE-2022-36254
all versions
Multiple persistent cross-site scripting (XSS) vulnerabilities in index.php in tramyardg Hotel Management System 1.0 allow remote
5.4MEDIUM
CVE-2022-2292
all versions
A vulnerability classified as problematic has been found in SourceCodester Hotel Management System 2.0. Affected is an unknown fun
3.5LOW
CVE-2022-2291
all versions
A vulnerability was found in SourceCodester Hotel Management System 2.0. It has been rated as problematic. This issue affects some
4.3MEDIUM
CVE-2022-28110
all versions
Hotel Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at the login page.
9.8CRITICAL
CVE-2022-27475
all versions
Cross site scripting (XSS) vulnerability in tramyardg hotel-mgmt-system, allows attackers to execute arbitrary code when /adm
6.1MEDIUM
CVE-2021-41651
all versions
A blind SQL injection vulnerability exists in the Raymart DG / Ahmed Helal Hotel-mgmt-system. A malicious attacker can retrieve se
7.5HIGH
threatengine.sh