Admerc develops a focused line of business-management applications spanning apartment, gym, event, and document systems, along with specialized ordering platforms, deployed across small-to-medium enterprises and service providers. The vendor's vulnerability profile skews strongly toward critical-severity outcomes, with the durable signal centered on injection-class weaknesses—SQL injection, cross-site scripting, code injection, and broader injection primitives—that recur across its product portfolio and reflect common input-handling and output-encoding gaps in web application design. These vulnerability classes are characteristic of application-layer risks in customer-facing and administrative interfaces where untrusted input flows directly into query construction, template rendering, or dynamic code execution without sufficient neutralization. Defenders deploying these systems should prioritize input validation and output encoding hardening, isolate affected applications from untrusted networks, and track this vendor's security releases closely given the severity concentration. Current exploitation activity, exposure counts, and severity breakdown are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Admerc over time
Signals from CVEs in this vendor scope (71 CVEs).
71 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-15165CRITICAL A vulnerability has been found in itsourcecode Online Cake Ordering System 1.0. The impacted element is an unknown function of the file /updatecustomer.php?action=edit. The manipul | Dec 29, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-14832CRITICAL A vulnerability was identified in itsourcecode Online Cake Ordering System 1.0. The affected element is an unknown function of the file /updateproduct.php?action=edit. Such manipul | Dec 17, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-14652CRITICAL A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This issue affects some unknown processing of the file /admindetail.php?action=edit. The manipulation of | Dec 14, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-14650CRITICAL A flaw has been found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown part of the file /cakeshop/product.php. Executing manipulation of the argument Produc | Dec 14, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-14649CRITICAL A vulnerability was detected in itsourcecode Online Cake Ordering System 1.0. Affected by this issue is some unknown functionality of the file /cakeshop/supplier.php. Performing ma | Dec 14, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-9730CRITICAL A vulnerability was found in itsourcecode Apartment Management System 1.0. The affected element is an unknown function of the file /ajax/updateProfile.php. The manipulation of the | Aug 31, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-9599CRITICAL A weakness has been identified in itsourcecode Apartment Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /setting/month_setup.php. Exe | Aug 29, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-9598CRITICAL A security flaw has been discovered in itsourcecode Apartment Management System 1.0. Affected is an unknown function of the file /setting/year_setup.php. Performing manipulation of | Aug 29, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-9594CRITICAL A vulnerability has been found in itsourcecode Apartment Management System 1.0. The affected element is an unknown function of the file /report/complain_info.php. The manipulation | Aug 28, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-9593CRITICAL A flaw has been found in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the file /report/unit_status_info.php. Executing manipulation of the argum | Aug 28, 2025 | 9.8 | 34 | NO | NO |
Signals from CVEs in this vendor scope (71 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Admerc.
Media articles that mention a CVE ID that affects a product developed by Admerc — matched by CVE ID, not by vendor name.