Projectworlds develops a focused suite of educational and enterprise management applications—including library management, online examination, timetabling, insurance, and travel systems—that collectively present a substantial vulnerability footprint despite the narrow product count. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes across its application portfolio. The exposure recurs durably through web-application input-handling weaknesses: SQL injection, cross-site scripting, code injection, unrestricted file uploads, and broader injection flaws that reflect insufficient sanitization of user-supplied data throughout the vendor's systems. Defenders should treat Projectworlds product deployments as high-risk targets for application-layer attack chains and prioritize input validation and output encoding controls in any environment running these systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Projectworlds over time
Signals from CVEs in this vendor scope (223 CVEs).
223 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8471CRITICAL A vulnerability, which was classified as critical, has been found in projectworlds Online Admission System 1.0. This issue affects some unknown processing of the file /adminlogin.p | Aug 2, 2025 | 9.8 | 42 | NO | YES |
CVE-2026-5368CRITICAL A vulnerability was determined in projectworlds Car Rental Project 1.0. The affected element is an unknown function of the file /login.php of the component Parameter Handler. This | Apr 2, 2026 | 9.8 | 39 | NO | NO |
CVE-2025-13572CRITICAL A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This affects an unknown part of the file /delete_admin.php. The manipulation of the argument | Nov 23, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-11604CRITICAL A vulnerability was determined in projectworlds Online Ordering Food System 1.0. This issue affects some unknown processing of the file /all-orders.php. This manipulation of the ar | Oct 11, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-11557CRITICAL A vulnerability has been found in projectworlds Gate Pass Management System 1.0. This issue affects some unknown processing of the file /add-pass.php. Such manipulation of the argu | Oct 9, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-11475CRITICAL A vulnerability was determined in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /view_member.php. Executing | Oct 8, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-9928CRITICAL A security flaw has been discovered in projectworlds Travel Management System 1.0. The impacted element is an unknown function of the file /viewcategory.php. Performing manipulatio | Sep 3, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-8947CRITICAL A vulnerability was found in projectworlds Visitor Management System 1.0. This issue affects some unknown processing of the file /query_data.php. The manipulation of the argument d | Aug 14, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-70146CRITICAL Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Generator 1.0 allows remote attackers to perform unauthorized admi | Feb 18, 2026 | 9.1 | 33 | NO | NO |
CVE-2026-0643CRITICAL A flaw has been found in projectworlds House Rental and Property Listing 1.0. Impacted is an unknown function of the file /app/register.php?action=reg of the component Signup. This | Jan 7, 2026 | 9.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (223 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Projectworlds.
Media articles that mention a CVE ID that affects a product developed by Projectworlds — matched by CVE ID, not by vendor name.