Janobe develops a focused line of school and financial management software serving educational institutions and payment processing, a portfolio that despite its modest product count occupies a prominent position in the vulnerability landscape due to widespread deployment in sensitive operational environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes across its school event management, attendance monitoring, baby care, and payment-card systems. The exposure recurs consistently through application-layer input-handling and access-control weaknesses, including SQL injection, cross-site scripting, injection flaws, unrestricted file uploads, and improper access control—patterns that reflect the web-application architecture common to school administration and financial transaction platforms. The concentration of critical severity in systems handling student records, attendance data, and payment credentials creates substantial risk for educational and financial institutions relying on these products. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Janobe over time
Signals from CVEs in this vendor scope (169 CVEs).
169 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13235CRITICAL A vulnerability was determined in itsourcecode Inventory Management System 1.0. This affects an unknown function of the file /admin/login.php. Executing manipulation of the argumen | Nov 16, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-12932CRITICAL A vulnerability was determined in SourceCodester Baby Care System 1.0. Affected by this issue is some unknown functionality of the file /admin.php?id=inbox. This manipulation of th | Nov 10, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-10596CRITICAL A vulnerability was found in SourceCodester Online Exam Form Submission 1.0. This affects an unknown part of the file /index.php. The manipulation of the argument usn results in sq | Sep 17, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-10482CRITICAL A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown function of the file /admin/index.php. The manipulation of the argu | Sep 15, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-9700CRITICAL A flaw has been found in SourceCodester Online Book Store 1.0. This issue affects some unknown processing of the file /publisher_list.php. This manipulation of the argument pubid c | Aug 30, 2025 | 9.8 | 34 | NO | NO |
CVE-2021-41646CRITICAL Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters.. | Oct 29, 2021 | 9.8 | 34 | NO | NO |
CVE-2025-12939CRITICAL A security flaw has been discovered in SourceCodester Interview Management System up to 1.0. Affected by this issue is some unknown functionality of the file /addCandidate.php. The | Nov 10, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-11487CRITICAL A security flaw has been discovered in SourceCodester Farm Management System 1.0. Affected by this issue is some unknown functionality of the file /uploadProduct.php. Performing ma | Oct 8, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-13257CRITICAL A security vulnerability has been detected in itsourcecode Inventory Management System 1.0. The affected element is an unknown function of the file /admin/user/index.php?view=edit. | Nov 17, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-13237CRITICAL A security flaw has been discovered in itsourcecode Inventory Management System 1.0. Affected is an unknown function of the file /LogSignModal.PHP. The manipulation of the argument | Nov 16, 2025 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (169 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Janobe.
Media articles that mention a CVE ID that affects a product developed by Janobe — matched by CVE ID, not by vendor name.