The Courier Management System Project maintains a focused web-based logistics platform where the durable vulnerability signal centers on application-layer input-handling issues, specifically SQL injection and cross-site scripting weaknesses. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Courier Management System Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-46198CRITICAL An SQL Injection vulnerability exists in Sourceodester Courier Management System 1.0 via the email parameter in /cms/ajax.php app. | Jan 21, 2022 | 9.8 | 24 | NO | NO |
CVE-2020-35327MEDIUM SQL injection vulnerability was discovered in Courier Management System 1.0, which can be exploited via the ref_no (POST) parameter to admin_class.php | Mar 4, 2021 | 6.5 | 22 | NO | NO |
CVE-2020-35329MEDIUM Courier Management System 1.0 1.0 is affected by SQL Injection via 'MULTIPART street '. | Mar 4, 2021 | 6.5 | 20 | NO | NO |
CVE-2020-35328MEDIUM Courier Management System 1.0 - 'First Name' Stored XSS | Mar 4, 2021 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Courier Management System Project.
Media articles that mention a CVE ID that affects a product developed by Courier Management System Project — matched by CVE ID, not by vendor name.