The Book Store Management System Project is a narrowly scoped application whose vulnerability profile skews strongly toward critical-severity outcomes across a focused product line. The recurring exposure clusters around web-application layer weaknesses including cross-site scripting, improper access control, missing authentication for critical functions, and sensitive-information disclosure, reflecting the authentication and input-handling demands of a data-driven management system. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Book Store Management System Project over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4229CRITICAL A vulnerability classified as critical was found in SourceCodester Book Store Management System 1.0. This vulnerability affects unknown code of the file /bsms_ci/index.php. The man | Nov 30, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-44097CRITICAL Book Store Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel. | Nov 30, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-49543CRITICAL Incorrect access control in Book Store Management System v1 allows attackers to access unauthorized pages and execute administrative functions without authenticating. | Mar 1, 2024 | 9.8 | 27 | NO | NO |
CVE-2022-4228HIGH A vulnerability classified as problematic has been found in SourceCodester Book Store Management System 1.0. This affects an unknown part of the file /bsms_ci/index.php/user/edit_u | Nov 30, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-45225MEDIUM Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute ar | Nov 25, 2022 | 6.1 | 22 | NO | NO |
CVE-2023-23024MEDIUM Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute ar | Jan 20, 2023 | 6.1 | 21 | NO | NO |
CVE-2022-3452MEDIUM A vulnerability was found in SourceCodester Book Store Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /category.php | Oct 11, 2022 | 5.4 | 21 | NO | NO |
CVE-2022-45217MEDIUM A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the | Dec 7, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-45215MEDIUM A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the | Dec 2, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-45613MEDIUM Book Store Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in /bsms_ci/index.php/book. This vulnerability allows attackers to execute ar | Jan 18, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Book Store Management System Project.
Media articles that mention a CVE ID that affects a product developed by Book Store Management System Project — matched by CVE ID, not by vendor name.