HOMEVULNERABILITIESVENDORSBarangay Management System Project

Barangay Management System ProjectCVEs & Vulnerabilities

9 CVEs affecting Barangay Management System Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

barangay management system 9
CVE-2024-25208MEDIUM

Barangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Resident function at /barangay-population-monitoring-system/masterlist.php. This vulnerabiity allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name parameter.

14 Feb 2024
5.4
CVSS
CVE-2024-25207MEDIUM

Barangay Population Monitoring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Resident function at /barangay-population-monitoring-system/masterlist.php. This vulnerabiity allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Contact Number parameter.

14 Feb 2024
5.4
CVSS
CVE-2022-43228HIGH

Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /clearance/clearance.php.

28 Oct 2022
7.2
CVSS
CVE-2022-35175CRITICAL

Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /blotter/blotter.php.

18 Aug 2022
9.8
CVSS
CVE-2022-34557HIGH

Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /pages/permit/permit.php.

29 Jul 2022
8.8
CVSS
CVE-2022-34120HIGH

Barangay Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the module editing function at /pages/activity/activity.php.

27 Jul 2022
7.2
CVSS
CVE-2022-34042HIGH

Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /pages/household/household.php.

20 Jul 2022
7.2
CVSS
CVE-2022-34024HIGH

Barangay Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the resident module editing function at /bmis/pages/resident/resident.php.

19 Jul 2022
7.2
CVSS
CVE-2022-34023CRITICAL

Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /officials/officials.php.

19 Jul 2022
9.8
CVSS
← PrevPage 1 / 1Next →