Kishan0725's vulnerability profile concentrates in a hospital management system product and skews strongly toward critical-severity outcomes across a set of application-layer weaknesses. The recurring exposure reflects common gaps in web-application security: SQL injection, cross-site scripting, authorization bypass, cross-site request forgery, and code injection—flaws that are endemic to healthcare software development and particularly consequential in environments where availability and data integrity carry patient-safety implications. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kishan0725 over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-41530CRITICAL Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php. | Aug 7, 2025 | 9.8 | 33 | NO | NO |
CVE-2023-41526CRITICAL Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func1.php via the username3 and password3 parameters. | Aug 7, 2025 | 9.8 | 32 | NO | NO |
CVE-2023-41525CRITICAL Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php. | Aug 7, 2025 | 9.8 | 31 | NO | NO |
CVE-2023-41528CRITICAL Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in contact.php via the txtname, txtphone, and txtmail parameters. | Aug 7, 2025 | 9.8 | 30 | NO | NO |
CVE-2023-41527CRITICAL Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the password2 parameter in func.php. | Aug 7, 2025 | 9.8 | 30 | NO | NO |
CVE-2023-43958CRITICAL An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management System v4.0 allows an unauthenticated attacker to upload any | Apr 22, 2025 | 9.8 | 29 | NO | NO |
CVE-2023-41532HIGH Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter in doctorsearch.php. | Aug 7, 2025 | 8.8 | 27 | NO | NO |
CVE-2023-41531HIGH Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the username1 and password2 parameters. | Aug 7, 2025 | 8.8 | 25 | NO | NO |
CVE-2023-40992MEDIUM Hospital Management System 4 is vulnerable to a SQL injection in /Hospital-Management-System-master/func.php via the password2 parameter. | Aug 7, 2025 | 6.5 | 24 | NO | NO |
CVE-2025-63513MEDIUM kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment cancellation functionality. | Nov 18, 2025 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kishan0725.
Media articles that mention a CVE ID that affects a product developed by Kishan0725 — matched by CVE ID, not by vendor name.