The Billing System Project maintains a narrowly scoped billing and accounting application where vulnerabilities cluster around web-application input handling, specifically SQL injection and improper file-upload validation. Treat this as a compact vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Billing System Project over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-43214CRITICAL Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at printOrder.php. | Nov 22, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-43213CRITICAL Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php. | Nov 23, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-43212CRITICAL Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php. | Nov 22, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-43215CRITICAL Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php. | Nov 22, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-41437HIGH Billing System Project v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/createProduct.php. | Sep 30, 2022 | 7.2 | 25 | NO | NO |
CVE-2022-41504HIGH An arbitrary file upload vulnerability in the component /php_action/editProductImage.php of Billing System Project v1.0 allows attackers to execute arbitrary code via a crafted PHP | Oct 18, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-41498HIGH Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editbrand.php. | Oct 17, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-41440HIGH Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editcategory.php. | Sep 30, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-41439HIGH Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/edituser.php. | Sep 30, 2022 | 7.2 | 19 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Billing System Project.
Media articles that mention a CVE ID that affects a product developed by Billing System Project — matched by CVE ID, not by vendor name.