Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Doctor Appointment System Project

First CVE: Feb 18, 2021Active for: 5 yearsTotal CVEs: 10
66.8
VTI Score
TOP TARGET

Doctor Appointment System Project maintains a narrowly scoped healthcare scheduling application that, despite limited product breadth, ranks among the more prominent vendors in the vulnerability landscape, likely reflecting widespread deployment across medical practice environments. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, concentrating in the application's web-facing input handling through recurring weakness classes of SQL injection and cross-site scripting. Defenders should treat updates to this system as high-priority given its direct access to patient data and scheduling infrastructure; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
5.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Doctor Appointment System Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 18, 2021
5 years ago
Most Recent CVE
Sep 11, 2023
1,051 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-27314CRITICAL
SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page.
Mar 5, 20219.846NOYES
CVE-2021-27320HIGH
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.
Mar 24, 20217.538NOYES
CVE-2021-27319HIGH
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter.
Mar 24, 20217.536NOYES
CVE-2021-27316HIGH
Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter.
Mar 24, 20217.536NOYES
CVE-2021-27315HIGH
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter.
Mar 24, 20217.536NOYES
CVE-2021-27124MEDIUM
SQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated patient user to dump the database credentials via a SQL inje
Feb 18, 20216.533NOYES
CVE-2023-39852CRITICAL
Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NOTE: this is disputed by a third party who claims that the us
Aug 15, 20239.827NONO
CVE-2023-40945CRITICAL
Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php.
Sep 11, 20239.825NONO
CVE-2021-27318MEDIUM
Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the lastname parameter
Mar 1, 20216.120NONO
CVE-2021-27317MEDIUM
Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the comment parameter.
Mar 1, 20216.120NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
30%
40%
30%
Severity distribution among all CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (80.0%)
Unknown0 (0.0%)
Required2 (20.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None9 (90.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
6 CVEs
60.0% of CVEs· 99th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Doctor Appointment System Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Doctor Appointment System Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Doctor Appointment System Project's Products

View all 1 CNAs →

Top CWEs