Doctor Appointment System Project maintains a narrowly scoped healthcare scheduling application that, despite limited product breadth, ranks among the more prominent vendors in the vulnerability landscape, likely reflecting widespread deployment across medical practice environments. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, concentrating in the application's web-facing input handling through recurring weakness classes of SQL injection and cross-site scripting. Defenders should treat updates to this system as high-priority given its direct access to patient data and scheduling infrastructure; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Doctor Appointment System Project over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27314CRITICAL SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page. | Mar 5, 2021 | 9.8 | 46 | NO | YES |
CVE-2021-27320HIGH Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter. | Mar 24, 2021 | 7.5 | 38 | NO | YES |
CVE-2021-27319HIGH Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter. | Mar 24, 2021 | 7.5 | 36 | NO | YES |
CVE-2021-27316HIGH Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter. | Mar 24, 2021 | 7.5 | 36 | NO | YES |
CVE-2021-27315HIGH Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter. | Mar 24, 2021 | 7.5 | 36 | NO | YES |
CVE-2021-27124MEDIUM SQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated patient user to dump the database credentials via a SQL inje | Feb 18, 2021 | 6.5 | 33 | NO | YES |
CVE-2023-39852CRITICAL Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NOTE: this is disputed by a third party who claims that the us | Aug 15, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-40945CRITICAL Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php. | Sep 11, 2023 | 9.8 | 25 | NO | NO |
CVE-2021-27318MEDIUM Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the lastname parameter | Mar 1, 2021 | 6.1 | 20 | NO | NO |
CVE-2021-27317MEDIUM Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the comment parameter. | Mar 1, 2021 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Doctor Appointment System Project.
Media articles that mention a CVE ID that affects a product developed by Doctor Appointment System Project — matched by CVE ID, not by vendor name.