The Garage Management System Project maintains a focused but prominently exposed web application for parking and vehicle management, placing a narrow but widely deployed product footprint in front of web browsers and administrative users. Vulnerabilities affecting the system skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency toward public exploit availability; the exposure reflects the application's role in handling user input, file uploads, and access control across administrative and customer interfaces. The recurring weakness classes—SQL injection, cross-site scripting, unrestricted file uploads, and improper access control—are characteristic of input-validation and privilege-management gaps in web applications managing user data and system permissions. Defenders should prioritize patching this vendor's updates given the severity tendency and the direct exposure of administrative and payment-handling functions; live exploitation, severity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Garage Management System Project over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36667HIGH Garage Management System 1.0 is vulnerable to the Remote Code Execution (RCE) due to the lack of filtering from the file upload function. The vulnerability exist during adding part | Sep 14, 2022 | 8.8 | 40 | NO | NO |
CVE-2022-2467CRITICAL A vulnerability has been found in SourceCodester Garage Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /login.php. The manipu | Jul 19, 2022 | 9.8 | 36 | NO | YES |
CVE-2022-2578CRITICAL A vulnerability, which was classified as critical, has been found in SourceCodester Garage Management System 1.0. This issue affects some unknown processing of the file /php_action | Jul 29, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-2577HIGH A vulnerability classified as critical was found in SourceCodester Garage Management System 1.0. This vulnerability affects unknown code of the file /edituser.php. The manipulation | Jul 29, 2022 | 8.8 | 29 | NO | NO |
CVE-2022-36161CRITICAL Orange Station 1.0 was discovered to contain a SQL injection vulnerability via the username parameter. | Jul 26, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-36636HIGH Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php. | Sep 2, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-2468HIGH A vulnerability was found in SourceCodester Garage Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /editbrand.php. The mani | Jul 19, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-37184HIGH The application manage_website.php on Garage Management System 1.0 is vulnerable to Shell File Upload. The already authenticated malicious user, can upload a dangerous RCE or LCE e | Aug 31, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-2672HIGH A vulnerability was found in SourceCodester Garage Management System. It has been classified as critical. Affected is an unknown function of the file createUser.php. The manipulati | Aug 5, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-2671HIGH A vulnerability was found in SourceCodester Garage Management System and classified as critical. This issue affects some unknown processing of the file removeUser.php. The manipula | Aug 5, 2022 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Garage Management System Project.
Media articles that mention a CVE ID that affects a product developed by Garage Management System Project — matched by CVE ID, not by vendor name.