The Employee Performance Evaluation System Project maintains a narrowly scoped human-resources application where the observed vulnerability signal centers on web-application input handling, specifically cross-site scripting and unrestricted file-upload issues. These weakness classes are characteristic of web-facing forms and document-handling features typical of HR management platforms; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Employee Performance Evaluation System Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-29625HIGH Employee Performance Evaluation System v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file upl | Apr 14, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-40435MEDIUM Employee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via adding new entries under the Departments and Designa | Dec 19, 2022 | 4.8 | 20 | NO | NO |
CVE-2020-35272MEDIUM Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Admin Portal in the Task and Description fields. | Jan 20, 2021 | 4.8 | 17 | NO | NO |
CVE-2020-35271MEDIUM Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Employees, First Name and Last Name fields. | Jan 20, 2021 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Employee Performance Evaluation System Project.
Media articles that mention a CVE ID that affects a product developed by Employee Performance Evaluation System Project — matched by CVE ID, not by vendor name.