Phptpoint develops a focused line of healthcare and communication management systems, including pharmacy and hospital platforms alongside mail-server infrastructure, all of which present input-handling attack surfaces. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and cluster around SQL injection and path-traversal weaknesses that reflect inadequate input sanitization and access-control boundaries in web-based business applications. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phptpoint over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-34954CRITICAL Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at invoiceprint.php. | Aug 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-34951CRITICAL Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getsalereport.php. | Aug 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2018-18705CRITICAL PhpTpoint hospital management system suffers from multiple SQL injection vulnerabilities via the index.php user parameter associated with LOGIN.php, or the rno parameter to ALIST.p | Oct 29, 2018 | 9.8 | 31 | NO | NO |
CVE-2022-34953CRITICAL Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the startDate parameter at getOrderReport.php. | Aug 2, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-34952CRITICAL Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at edituser.php. | Aug 2, 2022 | 9.8 | 29 | NO | NO |
CVE-2018-18704CRITICAL PhpTpoint Pharmacy Management System suffers from a SQL injection vulnerability in the index.php username parameter. | Oct 29, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-18703HIGH PhpTpoint Mailing Server Using File Handling 1.0 suffers from multiple Arbitrary File Read vulnerabilities in different sections that allow an attacker to read sensitive files on t | Oct 29, 2018 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phptpoint.
Media articles that mention a CVE ID that affects a product developed by Phptpoint — matched by CVE ID, not by vendor name.