Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Projectworlds

First CVE: Apr 6, 2020Active for: 6 yearsTotal CVEs: 223
50.8
VTI Score
TOP TARGET

Projectworlds develops a focused suite of educational and enterprise management applications—including library management, online examination, timetabling, insurance, and travel systems—that collectively present a substantial vulnerability footprint despite the narrow product count. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes across its application portfolio. The exposure recurs durably through web-application input-handling weaknesses: SQL injection, cross-site scripting, code injection, unrestricted file uploads, and broader injection flaws that reflect insufficient sanitization of user-supplied data throughout the vendor's systems. Defenders should treat Projectworlds product deployments as high-risk targets for application-layer attack chains and prioritize input validation and output encoding controls in any environment running these systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
223
Total CVEs
More Total CVEs than 100% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
9.0
Avg CVSS Score
Higher Avg CVSS Score than 87% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Projectworlds over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 6, 2020
6 years ago
Most Recent CVE
Apr 2, 2026
114 days ago

Products(45 total)

Top CVEs

Signals from CVEs in this vendor scope (223 CVEs).

223 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-8471CRITICAL
A vulnerability, which was classified as critical, has been found in projectworlds Online Admission System 1.0. This issue affects some unknown processing of the file /adminlogin.p
Aug 2, 20259.842NOYES
CVE-2026-5368CRITICAL
A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of the file /login.php of the component Parameter Handler. This
Apr 2, 20269.839NONO
CVE-2025-13572CRITICAL
A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This affects an unknown part of the file /delete_admin.php. The manipulation of the argument
Nov 23, 20259.834NONO
CVE-2025-11604CRITICAL
A vulnerability was determined in projectworlds Online Ordering Food System 1.0. This issue affects some unknown processing of the file /all-orders.php. This manipulation of the ar
Oct 11, 20259.834NONO
CVE-2025-11557CRITICAL
A vulnerability has been found in projectworlds Gate Pass Management System 1.0. This issue affects some unknown processing of the file /add-pass.php. Such manipulation of the argu
Oct 9, 20259.834NONO
CVE-2025-11475CRITICAL
A vulnerability was determined in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /view_member.php. Executing
Oct 8, 20259.834NONO
CVE-2025-9928CRITICAL
A security flaw has been discovered in projectworlds Travel Management System 1.0. The impacted element is an unknown function of the file /viewcategory.php. Performing manipulatio
Sep 3, 20259.834NONO
CVE-2025-8947CRITICAL
A vulnerability was found in projectworlds Visitor Management System 1.0. This issue affects some unknown processing of the file /query_data.php. The manipulation of the argument d
Aug 14, 20259.834NONO
CVE-2025-70146CRITICAL
Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized admi
Feb 18, 20269.133NONO
CVE-2026-0643CRITICAL
A flaw has been found in projectworlds House Rental and Property Listing 1.0. Impacted is an unknown function of the file /app/register.php?action=reg of the component Signup. This
Jan 7, 20269.833NONO
View all 223 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products223 CVEs
13%
16%
71%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network223 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low223 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None194 (87.0%)
Unknown0 (0.0%)
Required29 (13.0%)
Privileges Required
Low37 (16.6%)
High10 (4.5%)
None176 (78.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (223 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Projectworlds.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Projectworlds — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Projectworlds's Products

View all 3 CNAs →

Top CWEs