Hashenudara's vulnerability footprint centers on its eDoc Doctor Appointment System, a web-based medical scheduling and documentation platform vulnerable to application-layer weaknesses. The disclosures skew strongly toward critical-severity outcomes and recur across input-handling and request-validation flaws, including SQL injection, cross-site scripting, CSRF, and improper input validation, reflecting the exposure surface typical of healthcare web applications handling patient data and appointment workflows. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hashenudara over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36545CRITICAL Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/settings.php. | Aug 26, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-36544CRITICAL Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/booking.php. | Aug 26, 2022 | 9.8 | 31 | NO | NO |
CVE-2025-65358CRITICAL Edoc-doctor-appointment-system v1.0.1 was discovered to contain SQl injection vulnerability via the 'docid' parameter at /admin/appointment.php. | Dec 2, 2025 | 9.8 | 30 | NO | NO |
CVE-2022-36546HIGH Edoc-doctor-appointment-system v1.0.1 was discovered to contain a Cross-Site Request Forgery (CSRF) via /patient/settings.php. | Aug 26, 2022 | 8.8 | 28 | NO | NO |
CVE-2025-66918HIGH edoc-doctor-appointment-system v1.0.1 is vulnerable to Cross Site Scripting (XSS) in admin/add-session.php via the "title" parameter. | Dec 11, 2025 | 8.8 | 27 | NO | NO |
CVE-2022-36543CRITICAL Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/doctors.php. | Aug 26, 2022 | 9.8 | 24 | NO | NO |
CVE-2022-36542MEDIUM An access control issue in the component /ip/admin/ of Edoc-doctor-appointment-system v1.0.1 allows attackers to arbitrarily edit, read, and delete Administrator data. | Aug 26, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-36547MEDIUM Edoc-doctor-appointment-system v1.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /patient/index.php. This vulnerability allows attackers to e | Aug 26, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-36548MEDIUM Edoc-doctor-appointment-system v1.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability at /patient/settings.php. This vulnerability allows attackers to e | Aug 26, 2022 | 5.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hashenudara.
Media articles that mention a CVE ID that affects a product developed by Hashenudara — matched by CVE ID, not by vendor name.