Tailor Management System Project maintains a focused tailoring and garment-management application that serves boutiques and small fashion retailers, with its vulnerability disclosures concentrated in that single product line. The recurring exposure centers on web-application input-handling weaknesses—SQL injection, cross-site scripting, and out-of-bounds reads—that are characteristic of business applications processing user-supplied garment specifications and customer data, and public exploit code has been developed for vulnerabilities in this product. Defenders deploying this application should prioritize input validation and output encoding patches; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tailor Management System Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-23835MEDIUM A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Management System v1.0 allows remote attackers to harvest keys p | Sep 1, 2020 | 6.1 | 30 | NO | YES |
CVE-2020-36077HIGH SQL injection vulnerability found in Tailor Mangement System v.1 allows a remote attacker to execute arbitrary code via the customer parameter of the orderadd.php file | Apr 10, 2023 | 8.8 | 28 | NO | NO |
CVE-2020-36074HIGH SQL injection vulnerability found in Tailor Mangement System v.1 allows a remote attacker to execute arbitrary code via the title parameter. | Apr 6, 2023 | 8.8 | 27 | NO | NO |
CVE-2020-36073HIGH SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via the detail parameter of the document.php page. | Apr 6, 2023 | 8.8 | 27 | NO | NO |
CVE-2020-36072HIGH SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via the id parameter. | Apr 6, 2023 | 8.8 | 27 | NO | NO |
CVE-2020-36071HIGH SQL injection vulnerability found in Tailor Management System v.1 allows a remote authenticated attacker to execute arbitrary code via the customer parameter of the email.php page. | Apr 6, 2023 | 8.8 | 27 | NO | NO |
CVE-2021-40260MEDIUM Multiple Cross Site Scripting (XSS) vulnerabilities exist in SourceCodester Tailor Management 1.0 via the (1) eid parameter in (a) partedit.php and (b) customeredit.php, the (2) id | Nov 8, 2021 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tailor Management System Project.
Media articles that mention a CVE ID that affects a product developed by Tailor Management System Project — matched by CVE ID, not by vendor name.