Mayurik's vulnerability footprint concentrates in a small set of business-management applications spanning property rental, salon operations, pet grooming, legal practice, and travel booking—all web-facing products serving small to mid-sized operations. Despite a focused product portfolio, the vendor's disclosures are disproportionately represented in the landscape and skew strongly toward critical-severity outcomes, reflecting deep architectural weaknesses across its application stack. The exposure recurs consistently through injection-family flaws—SQL injection, cross-site scripting, code injection, and generic injection—alongside unrestricted file uploads, indicating systemic deficiencies in input validation, output encoding, and file-handling logic that span multiple products and versions. These weakness classes are characteristic of web applications that have grown without mature security practices; defenders deploying any of these management systems should treat patches as high-priority and audit deployed instances for active exploitation patterns, since the attack surface is Internet-reachable and the consequences of compromise affect multi-tenant data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mayurik over time
Signals from CVEs in this vendor scope (274 CVEs).
274 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-27747CRITICAL File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Image parameter in the profile.php | Mar 1, 2024 | 9.8 | 47 | NO | YES |
CVE-2024-27746CRITICAL SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.p | Mar 1, 2024 | 9.8 | 40 | NO | YES |
CVE-2025-12597CRITICAL A vulnerability was detected in SourceCodester Best House Rental Management System 1.0. Affected by this vulnerability is the function save_category of the file /admin_class.php. P | Nov 2, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-10688CRITICAL A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/operation/paid.php. This manipulat | Sep 18, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-9426CRITICAL A weakness has been identified in itsourcecode Online Tour and Travel Management System 1.0. This affects an unknown part of the file /package.php. Executing manipulation of the ar | Aug 25, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-9154CRITICAL A flaw has been found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown processing of the file /user/page-login.php. This manipulation o | Aug 19, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-8984CRITICAL A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Affected is an unknown function of the file /admin/operations/expense_category.php. The | Aug 14, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-8969CRITICAL A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/approve_user.ph | Aug 14, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-9425CRITICAL A security flaw has been discovered in itsourcecode Online Tour and Travel Management System 1.0. Affected by this issue is some unknown functionality of the file /enquiry.php. Per | Aug 25, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-9155CRITICAL A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Impacted is an unknown function of the file /user/forget_password.php. Such manipulatio | Aug 19, 2025 | 9.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (274 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mayurik.
Media articles that mention a CVE ID that affects a product developed by Mayurik — matched by CVE ID, not by vendor name.