The Stock Management System Project maintains a focused, single-product vulnerability footprint centered on its stock management system, which despite a narrow scope occupies a position among more prominent software products tracked in the landscape. Vulnerabilities affecting this system skew strongly toward critical-severity outcomes and recur through application-layer weakness classes including cross-site scripting, SQL injection, cross-site request forgery, and authorization flaws—patterns endemic to web-facing business software with user input and database interaction. Defenders should apply patches from this vendor promptly given the severity tendency; live exploitation activity and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Stock Management System Project over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4088CRITICAL A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some unknown functionality of the file /pages/processlogin.php. Th | Nov 24, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-4090HIGH A vulnerability was found in rickxy Stock Management System and classified as problematic. This issue affects some unknown processing of the file us_transac.php?action=add. The man | Nov 24, 2022 | 8.8 | 28 | NO | NO |
CVE-2020-24197CRITICAL A SQL injection vulnerability in the login component in Stock Management System v1.0 allows remote attacker to execute arbitrary SQL commands via the username parameter. | Sep 9, 2020 | 9.8 | 28 | NO | NO |
CVE-2024-36779CRITICAL Sourcecodester Stock Management System v1.0 is vulnerable to SQL Injection via editCategories.php. | Jun 6, 2024 | 9.8 | 27 | NO | NO |
CVE-2023-51951CRITICAL SQL Injection vulnerability in Stock Management System 1.0 allows a remote attacker to execute arbitrary code via the id parameter in the manage_bo.php file. | Feb 5, 2024 | 9.8 | 24 | NO | NO |
CVE-2022-4089MEDIUM A vulnerability was found in rickxy Stock Management System. It has been declared as problematic. This vulnerability affects unknown code of the file /pages/processlogin.php. The m | Nov 24, 2022 | 5.4 | 21 | NO | NO |
CVE-2020-23830HIGH A Cross-Site Request Forgery (CSRF) vulnerability in changeUsername.php in SourceCodester Stock Management System v1.0 allows remote attackers to deny future logins by changing an | Sep 2, 2020 | 7.1 | 21 | NO | NO |
CVE-2021-44114MEDIUM Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Stock Management System in PHP/OOP 1.0, which allows remote malicious users to execute arbitrary remote code execu | Jan 31, 2022 | 4.8 | 19 | NO | NO |
CVE-2020-24198MEDIUM A persistent cross-site scripting vulnerability in Sourcecodester Stock Management System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'Brand Name.' | Sep 9, 2020 | 6.1 | 17 | NO | NO |
CVE-2020-23831MEDIUM A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Stock Management System v1.0 allows remote attackers to harvest login c | Sep 1, 2020 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Stock Management System Project.
Media articles that mention a CVE ID that affects a product developed by Stock Management System Project — matched by CVE ID, not by vendor name.