The Vehicle Booking System Project operates a focused transportation-booking platform with a niche deployment footprint, where the observed vulnerability exposure centers on web-application input handling and file-upload mechanisms. The recurring weaknesses—cross-site scripting flaws in page generation and unrestricted file uploads—reflect common risks in web-facing booking and user-management functionality. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vehicle Booking System Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-43083HIGH An arbitrary file upload vulnerability in admin-add-vehicle.php of Vehicle Booking System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | Nov 1, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-43084MEDIUM A cross-site scripting (XSS) vulnerability in admin-add-vehicle.php of Vehicle Booking System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload i | Nov 1, 2022 | 4.8 | 19 | NO | NO |
CVE-2024-0345MEDIUM A vulnerability, which was classified as problematic, was found in CodeAstro Vehicle Booking System 1.0. This affects an unknown part of the file usr/usr-register.php of the compon | Jan 9, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-0346MEDIUM A vulnerability has been found in CodeAstro Vehicle Booking System 1.0 and classified as problematic. This vulnerability affects unknown code of the file usr/user-give-feedback.php | Jan 9, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vehicle Booking System Project.
Media articles that mention a CVE ID that affects a product developed by Vehicle Booking System Project — matched by CVE ID, not by vendor name.