Carmelogarcia maintains a narrow but diverse portfolio of web-based business applications spanning logistics, human resources, food service, and matrimonial services, each representing a distinct attack surface. Despite this focused product scope, the vendor's vulnerabilities skew strongly toward critical-severity outcomes, concentrated in foundational weakness classes such as SQL injection, cross-site scripting, code injection, and improper access control that are endemic to web application development. These recurring classes point to consistent input-validation and output-encoding gaps across the product line, reflecting vulnerabilities that are typically straightforward to exploit once discovered. Defenders should treat patches from this vendor as priority fixes for affected applications, particularly where they handle user input or access control; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Carmelogarcia over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-11553CRITICAL A weakness has been identified in code-projects Courier Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-courier.php. Executing ma | Oct 9, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-13303CRITICAL A vulnerability was determined in code-projects Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /search-edit.php. This manipulation | Nov 17, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-13302CRITICAL A vulnerability was identified in code-projects Courier Management System 1.0. This affects an unknown part of the file /add-new-officer.php. Such manipulation of the argument Mana | Nov 17, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-12316CRITICAL A vulnerability was identified in code-projects Courier Management System 1.0. This impacts an unknown function of the file /courier/edit-courier.php. The manipulation of the argum | Oct 27, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-13396CRITICAL A weakness has been identified in code-projects Courier Management System 1.0. This affects an unknown function of the file /add-office.php. This manipulation of the argument Offic | Nov 19, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-6124CRITICAL A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. This issue affects some unknown processing of the file /tablelow.php. The manipul | Jun 16, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-5980CRITICAL A vulnerability classified as critical was found in code-projects Restaurant Order System 1.0. This vulnerability affects unknown code of the file /order.php. The manipulation of t | Jun 10, 2025 | 9.8 | 29 | NO | NO |
CVE-2024-10608CRITICAL A vulnerability was found in code-projects Courier Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /login.php. The mani | Nov 1, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-10607CRITICAL A vulnerability was found in code-projects Courier Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /track-result.php. T | Nov 1, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-6651CRITICAL A vulnerability was found in code-projects Matrimonial Site 1.0. It has been classified as critical. Affected is an unknown function of the file /auth/auth.php?user=1. The manipula | Dec 10, 2023 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Carmelogarcia.
Media articles that mention a CVE ID that affects a product developed by Carmelogarcia — matched by CVE ID, not by vendor name.