The Online Examination System Project maintains a web-based assessment platform whose vulnerability profile centers on a narrow product scope but exhibits an elevated tendency toward critical-severity outcomes. The recurring exposure reflects characteristic web-application flaws: cross-site scripting, cross-site request forgery, and SQL injection arising from inadequate input handling and request validation in an internet-facing educational tool. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Online Examination System Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-45111CRITICAL Online Examination System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'email' parameter of the feed.php resource does not validate the charact | Nov 2, 2023 | 9.8 | 28 | NO | NO |
CVE-2020-26006MEDIUM Project Worlds Online Examination System 1.0 is affected by Cross Site Scripting (XSS) via account.php. | May 24, 2021 | 6.1 | 21 | NO | NO |
CVE-2020-25411MEDIUM Projectworlds Online Examination System 1.0 is vulnerable to CSRF, which allows a remote attacker to delete the existing user. | May 24, 2021 | 6.5 | 21 | NO | NO |
CVE-2020-29258MEDIUM Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the w parameter to index.php. | Dec 9, 2020 | 6.1 | 20 | NO | NO |
CVE-2020-29257MEDIUM Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the q parameter to feedback.php. | Dec 9, 2020 | 6.1 | 20 | NO | NO |
CVE-2023-36256MEDIUM The Online Examination System Project 1.0 version is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker can craft a malicious link that, when clicked by an admin | Jul 7, 2023 | 6.5 | 19 | NO | NO |
CVE-2020-29259MEDIUM Cross-site scripting (XSS) vulnerability in Online Examination System 1.0 via the subject or feedback parameter to feedback.php. | Dec 9, 2020 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Online Examination System Project.
Media articles that mention a CVE ID that affects a product developed by Online Examination System Project — matched by CVE ID, not by vendor name.