The Pharmacy Management System Project maintains a healthcare software application where vulnerabilities skew strongly toward critical-severity outcomes. The recurring exposure centers on SQL injection and improper file-upload handling, weakness classes that are particularly consequential in healthcare settings where data integrity and system availability directly affect patient safety. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pharmacy Management System Project over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-30887CRITICAL Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows | May 20, 2022 | 9.8 | 36 | NO | NO |
CVE-2022-34947CRITICAL Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editcategory.php. | Aug 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-0918CRITICAL A vulnerability has been found in codeprojects Pharmacy Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file add.php of the compone | Feb 19, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-34950CRITICAL Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editproduct.php. | Aug 2, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-34949CRITICAL Pharmacy Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the email or password parameter at login.php. | Aug 2, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-34946CRITICAL Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getexpproduct.php. | Aug 2, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-34945CRITICAL Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getproductreport.php. | Aug 2, 2022 | 9.8 | 30 | NO | NO |
CVE-2024-8138CRITICAL A vulnerability, which was classified as critical, was found in code-projects Pharmacy Management System 1.0. Affected is the function editManager of the file /index.php?action=edi | Aug 25, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-31519CRITICAL Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the email parameter at login_core.php. | May 16, 2023 | 9.8 | 29 | NO | NO |
CVE-2024-8146CRITICAL A vulnerability has been found in code-projects Pharmacy Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /index.php?action=edi | Aug 25, 2024 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pharmacy Management System Project.
Media articles that mention a CVE ID that affects a product developed by Pharmacy Management System Project — matched by CVE ID, not by vendor name.