The Prison Management System Project maintains a single, specialized correctional-facility management application that serves a critical government function but operates in a narrower deployment context than commercial enterprise software. The vulnerability profile concentrates on a small set of application-layer weaknesses: SQL injection, improper authorization, cross-site scripting, and insufficiently protected credentials recur across disclosures, reflecting input-validation and access-control gaps typical of web-based administrative systems. These weakness classes are particularly material in a correctional context, where unauthorized access or data manipulation carries direct public-safety and operational consequences; defenders should prioritize patching and implement defense-in-depth controls around authentication, input handling, and database access. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Prison Management System Project over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-32405HIGH Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/view_prison.php:4 | Jun 24, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-32404HIGH Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_inmate.php:3 | Jun 24, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-32403HIGH Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_record.php:4 | Jun 24, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-32402HIGH Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/manage_prison.php:4 | Jun 24, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-32399HIGH Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/view_crime.php:4 | Jun 24, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-32396HIGH Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/manage_visit.php:4 | Jun 24, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-32395HIGH Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/manage_crime.php:4 | Jun 24, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-32394HIGH Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/view_inmate.php:3 | Jun 24, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-32392HIGH Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/manage_action.php:4 | Jun 24, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-32391HIGH Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/view_action.php:4 | Jun 24, 2022 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Prison Management System Project.
Media articles that mention a CVE ID that affects a product developed by Prison Management System Project — matched by CVE ID, not by vendor name.