Campcodes develops a suite of web-based management and transaction systems spanning school administration, inventory, recruitment, and service-industry operations, a portfolio that exposes a broad range of customer-facing and administrative interfaces. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and concentrate in input-handling and code-generation weaknesses endemic to web applications: SQL injection, cross-site scripting, injection flaws, unsafe file uploads, and code injection. These weakness classes recur across the vendor's product line and reflect fundamental validation and sanitization gaps that can enable unauthorized data access, session hijacking, and remote code execution in education, retail, and staffing environments where these systems manage sensitive records and transactions. Defenders should treat Campcodes advisories as high-priority for any deployed instances and emphasize input validation hardening and web application firewall protections. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Campcodes over time
Signals from CVEs in this vendor scope (575 CVEs).
575 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9744CRITICAL A weakness has been identified in Campcodes Online Loan Management System 1.0. The affected element is an unknown function of the file /ajax.php?action=login. Executing manipulatio | Aug 31, 2025 | 9.8 | 43 | NO | YES |
CVE-2023-39115CRITICAL install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document. | Aug 16, 2023 | 9.8 | 39 | NO | YES |
CVE-2025-5298CRITICAL A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affected is an unknown function of the file /admin/betweendates-det | May 28, 2025 | 9.8 | 38 | NO | YES |
CVE-2025-15207CRITICAL A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/view_products.php. The manipulation of the argument c | Dec 29, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-14952CRITICAL A vulnerability was detected in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_category.php. Performing a manipulation of the arg | Dec 19, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-14877CRITICAL A vulnerability was identified in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_retailer.php. The manipulation of the argument c | Dec 18, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-13557CRITICAL A vulnerability has been found in Campcodes Online Polling System 1.0. Affected by this issue is some unknown functionality of the file /registeracc.php. The manipulation of the ar | Nov 23, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-13411CRITICAL A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Pe | Nov 19, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-13291CRITICAL A vulnerability was found in Campcodes Supplier Management System 1.0. This affects an unknown part of the file /manufacturer/confirm_order.php. Performing a manipulation of the ar | Nov 17, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-11595CRITICAL A vulnerability was found in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function of the file /admin-profile.php. Performing a manipulation of | Oct 11, 2025 | 9.8 | 34 | NO | NO |
Signals from CVEs in this vendor scope (575 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Campcodes.
Media articles that mention a CVE ID that affects a product developed by Campcodes — matched by CVE ID, not by vendor name.