The Online Banking System Project maintains a single, security-critical financial application whose vulnerability profile concentrates in SQL injection—a class of flaw that can directly compromise authentication, data confidentiality, and transactional integrity. Vulnerabilities affecting this product skew strongly toward critical-severity outcomes, reflecting the high-value attack surface and regulatory exposure inherent to banking systems. Defenders should treat patches for this vendor as emergency-priority given the financial and customer-data implications; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Online Banking System Project over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40118CRITICAL Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/send_funds_action.php. | Sep 23, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-40115CRITICAL Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/delete_beneficiary.php. | Sep 23, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-23363CRITICAL Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via index.php. | Jan 21, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-40122CRITICAL Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/edit_customer_action.php. | Sep 23, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-40121CRITICAL Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/manage_customers.php. | Sep 23, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-40120CRITICAL Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net-banking/customer_transactions.php. | Sep 23, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-40119CRITICAL Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search_term parameter at /net-banking/transactions.php. | Sep 23, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-40117CRITICAL Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/delete_customer.php. | Sep 23, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-40116CRITICAL Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/beneficiary.php. | Sep 23, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-28116CRITICAL Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter. | Apr 5, 2022 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Online Banking System Project.
Media articles that mention a CVE ID that affects a product developed by Online Banking System Project — matched by CVE ID, not by vendor name.