1000projects develops a portfolio of academic and small-business management applications, including systems for beauty parlours, bookstores, student projects, and attendance tracking, that typically run in educational or hosted environments. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and concentrate heavily in input-handling and access-control weaknesses, particularly SQL injection, cross-site scripting, code injection, and improper access controls that are characteristic of web applications built without systematic input sanitization and privilege enforcement. The modest product count belies the vendor's prominence in the vulnerability landscape, reflecting the widespread adoption of these applications in academic institutions and the severity of the flaws affecting them. Defenders deploying any of these systems should prioritize urgent patching of injection and access-control vulnerabilities and audit instance exposure on untrusted networks; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 1000projects over time
Signals from CVEs in this vendor scope (86 CVEs).
86 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9444CRITICAL A vulnerability has been found in 1000projects Online Project Report Submission and Evaluation System 1.0. This issue affects some unknown processing of the file /admin/controller/ | Aug 26, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-10833CRITICAL A vulnerability was determined in 1000projects Bookstore Management System 1.0. The impacted element is an unknown function of the file /login.php. This manipulation of the argumen | Sep 23, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-10424CRITICAL A vulnerability was determined in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The affected element is an unknown function of the file /admin/co | Sep 15, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-8241CRITICAL A vulnerability, which was classified as critical, was found in 1000 Projects ABC Courier Management System 1.0. This affects an unknown part of the file /report.php. The manipulat | Jul 27, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-10425CRITICAL A vulnerability was identified in 1000projects Online Student Project Report Submission and Evaluation System 1.0. The impacted element is an unknown function of the file /admin/co | Sep 15, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-9930CRITICAL A security vulnerability has been detected in 1000projects Beauty Parlour Management System 1.0. This impacts an unknown function of the file /admin/contact-us.php. The manipulatio | Sep 4, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-9919CRITICAL A vulnerability was identified in 1000projects Beauty Parlour Management System 1.0. This affects an unknown function of the file /admin/bwdates-reports-details.php. The manipulati | Sep 3, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-8935CRITICAL A vulnerability was found in 1000 Projects Sales Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /superstore/custcmp.php. The manipula | Aug 14, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-8932CRITICAL A vulnerability was determined in 1000 Projects Sales Management System 1.0. This vulnerability affects unknown code of the file /superstore/admin/sales.php. The manipulation of th | Aug 14, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-0847CRITICAL A vulnerability was found in 1000 Projects Employee Task Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /index.php of | Jan 30, 2025 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (86 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 1000projects.
Media articles that mention a CVE ID that affects a product developed by 1000projects — matched by CVE ID, not by vendor name.