Kashipara develops a focused line of web-based business and service-management applications spanning food ordering, billing, travel booking, job placement, and institutional notice systems, a portfolio that concentrates across a modestly sized but well-represented vendor footprint. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur consistently through foundational web-application weakness classes: SQL injection, cross-site scripting, and unrestricted file upload, reflecting common architectural patterns in custom web platforms. These weakness classes sit at the intersection of input handling and data processing, and their prevalence across multiple product lines suggests systemic patterns in how the vendor approaches input validation and file handling in its application tier. Defenders deploying any of this vendor's products should treat input sanitization and upload restrictions as high-priority hardening areas; current severity, exploitation, and remediation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kashipara over time
Signals from CVEs in this vendor scope (56 CVEs).
56 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-0289CRITICAL A vulnerability classified as critical was found in Kashipara Food Management System 1.0. This vulnerability affects unknown code of the file stock_entry_submit.php. The manipulati | Jan 8, 2024 | 9.8 | 30 | NO | NO |
CVE-2023-50865CRITICAL Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'city' parameter of the hotelSearch.php resource does not validate the characters r | Jan 4, 2024 | 9.8 | 30 | NO | NO |
CVE-2023-49658CRITICAL Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'bank_details' parameter of the party_submit.php resource does not validate the c | Jan 4, 2024 | 9.8 | 30 | NO | NO |
CVE-2023-49624CRITICAL Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cancelid' parameter of the material_bill.php resource does not validate the char | Jan 4, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-0493CRITICAL A vulnerability, which was classified as critical, has been found in Kashipara Billing Software 1.0. Affected by this issue is some unknown functionality of the file submit_deliver | Jan 13, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-49681CRITICAL Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'cmbQual' parameter of the Employer/InsertWalkin.php resource does not validate the cha | Dec 21, 2023 | 9.8 | 29 | NO | NO |
CVE-2024-0492CRITICAL A vulnerability classified as critical was found in Kashipara Billing Software 1.0. Affected by this vulnerability is an unknown functionality of the file buyer_detail_submit.php o | Jan 13, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-0290CRITICAL A vulnerability, which was classified as critical, has been found in Kashipara Food Management System 1.0. This issue affects some unknown processing of the file stock_edit.php. Th | Jan 8, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-0288CRITICAL A vulnerability classified as critical has been found in Kashipara Food Management System 1.0. This affects an unknown part of the file rawstock_used_damaged_submit.php. The manipu | Jan 8, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-0287CRITICAL A vulnerability was found in Kashipara Food Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file itemBillPdf.php. | Jan 7, 2024 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (56 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kashipara.
Media articles that mention a CVE ID that affects a product developed by Kashipara — matched by CVE ID, not by vendor name.