The Barangay Management System Project maintains a single, locally deployed municipal administration platform that serves as the authoritative system for community-level governance records and services in the Philippines. Vulnerabilities affecting this vendor skew toward serious outcomes, concentrating in the core barangay management application through recurring input-handling weaknesses including SQL injection, cross-site scripting, and unrestricted file uploads that are endemic to web-based administrative systems. Defenders operating or auditing this system should prioritize remediation of these application-layer flaws, particularly where the platform handles sensitive resident data; current severity and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Barangay Management System Project over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34120HIGH Barangay Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the module editing function at /pages/activity/activity.php. | Jul 27, 2022 | 7.2 | 31 | NO | NO |
CVE-2022-34023CRITICAL Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /officials/officials.php. | Jul 19, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-35175CRITICAL Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /blotter/blotter.php. | Aug 18, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-34557HIGH Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /pages/permit/permit.php. | Jul 28, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-34024HIGH Barangay Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the resident module editing function at /bmis/pages/resident/resident.php. | Jul 19, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-43228HIGH Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /clearance/clearance.php. | Oct 28, 2022 | 7.2 | 23 | NO | NO |
CVE-2022-34042HIGH Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /pages/household/household.php. | Jul 20, 2022 | 7.2 | 23 | NO | NO |
CVE-2024-25208MEDIUM Barangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Resident function at /barangay-population-monitoring-syst | Feb 14, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-25207MEDIUM Barangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Resident function at /barangay-population-monitoring-syst | Feb 14, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Barangay Management System Project.
Media articles that mention a CVE ID that affects a product developed by Barangay Management System Project — matched by CVE ID, not by vendor name.