Oretnom23's vulnerability footprint spans a moderate but broadly represented collection of web-based business and administrative applications, including e-commerce platforms, management systems for human resources and laboratory operations, and food-ordering solutions that serve educational and commercial environments. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and concentrate heavily in application-layer input handling, encompassing SQL injection, cross-site scripting, injection flaws, unrestricted file uploads, and cross-site request forgery—a cluster of weaknesses typical of web applications with insufficient input validation and output encoding. The recurring pattern reflects a structural vulnerability in the vendor's development practices: these weakness classes are persistent across multiple distinct product lines, indicating that foundational security controls around parameterized queries, context-aware output encoding, and file-type validation are not uniformly applied. Defenders should treat Oretnom23 product deployments as high-risk and prioritize remediation of SQL-injection and XSS findings, given the vendor's sustained exposure to these classes and the critical outcomes they tend to produce. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oretnom23 over time
Signals from CVEs in this vendor scope (761 CVEs).
761 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40471CRITICAL Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functionality in users.php | Oct 31, 2022 | 9.8 | 52 | NO | YES |
CVE-2021-42580CRITICAL Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) | Nov 15, 2021 | 9.8 | 47 | NO | YES |
CVE-2023-1826CRITICAL A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. This affects an unknown part of the file php-ocls\admin\system_ | Apr 4, 2023 | 9.8 | 44 | NO | YES |
CVE-2021-44653CRITICAL Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due to SQL injection vulnerabilit | Dec 15, 2021 | 9.8 | 43 | NO | YES |
CVE-2021-43140CRITICAL SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login. | Nov 3, 2021 | 9.8 | 43 | NO | YES |
CVE-2023-33592CRITICAL Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information. | Jun 28, 2023 | 9.8 | 39 | NO | YES |
CVE-2022-2297HIGH A vulnerability, which was classified as critical, was found in SourceCodester Clinics Patient Management System 2.0. Affected is an unknown function of the file /pms/update_user.p | Jul 12, 2022 | 8.8 | 39 | NO | YES |
CVE-2023-34581CRITICAL Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2 | Jun 12, 2023 | 9.8 | 38 | NO | YES |
CVE-2024-0264CRITICAL A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /LoginRegistration.php. | Jan 7, 2024 | 9.8 | 37 | NO | NO |
CVE-2026-2848CRITICAL A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=register | Feb 20, 2026 | 9.8 | 35 | NO | NO |
Signals from CVEs in this vendor scope (761 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oretnom23.
Media articles that mention a CVE ID that affects a product developed by Oretnom23 — matched by CVE ID, not by vendor name.