Carmelo maintains a portfolio of web-based ordering, management, and community-engagement applications including pizza ordering systems, donation platforms, membership management, and event judging tools. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and concentrate across a consistent set of input-handling and code-execution weakness classes: SQL injection, cross-site scripting, injection flaws, code injection, and unrestricted file uploads are the dominant exposure patterns. These are structural weaknesses endemic to web applications that process user input without adequate sanitization and validation, reflecting a pattern of unsafe handling at multiple layers—from database queries to output generation to file acceptance. Defenders should treat updates for this vendor's products as high-priority when these systems face internet or untrusted-network exposure, particularly where they manage sensitive data or control operational workflows. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Carmelo over time
Signals from CVEs in this vendor scope (127 CVEs).
127 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-60307CRITICAL code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field on the login page can bypass login attempt | Oct 10, 2025 | 9.8 | 37 | NO | NO |
CVE-2026-0700CRITICAL A vulnerability was determined in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /intern/admin/check_admin.php. Executing a mani | Jan 8, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-15011CRITICAL A vulnerability was found in code-projects Simple Stock System 1.0. Impacted is an unknown function of the file /logout.php. The manipulation of the argument uname results in sql i | Dec 22, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-14647CRITICAL A weakness has been identified in code-projects Computer Book Store 1.0. Affected is an unknown function of the file /admin_delete.php. This manipulation of the argument bookisbn c | Dec 14, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-14223CRITICAL A vulnerability has been found in code-projects Simple Leave Manager 1.0. Affected by this vulnerability is an unknown functionality of the file /request.php. Such manipulation of | Dec 8, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-13323CRITICAL A security flaw has been discovered in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /listorder.php. Performing manipulation of the ar | Nov 18, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-11556CRITICAL A flaw has been found in code-projects Simple Leave Manager 1.0. This vulnerability affects unknown code of the file /user.php. This manipulation of the argument table causes sql i | Oct 9, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-10103CRITICAL A weakness has been identified in code-projects Online Event Judging System 1.0. This impacts an unknown function of the file /home.php. Executing manipulation of the argument main | Sep 8, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-8493CRITICAL A vulnerability classified as critical was found in code-projects Intern Membership Management System 1.0. This vulnerability affects unknown code of the file /admin/edit_student_q | Aug 2, 2025 | 9.8 | 34 | NO | NO |
CVE-2026-5019CRITICAL A security vulnerability has been detected in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file all-orders.php of t | Mar 29, 2026 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (127 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Carmelo.
Media articles that mention a CVE ID that affects a product developed by Carmelo — matched by CVE ID, not by vendor name.