Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

Human Resource Management System — Vulnerabilities & Security Advisories 25

All 25 CVE vulnerabilities found in Human Resource Management System, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities for Human Resource Management System software, categorized by Common Weakness Enumerations and associated vendor advisories. It collects security flaw data spanning from the early 2010s to the present, covering zero-day exploits, logic errors, and standard configuration weaknesses affecting enterprise HR platforms. Users can track a vendor's advisories to stay informed about patch timelines, understand a weakness class by examining recurring patterns across different implementations, and look up a product's vulnerability history to assess long-term security posture. The aggregation focuses on providing a clear, chronological view of how specific HR management tools have been compromised, including issues related to authentication bypass, insecure direct object references, and privilege escalation. By centralizing this information, the page helps security professionals and IT administrators identify trends, compare remediation efforts across similar systems, and prioritize updates based on historical impact and availability. This resource does not guarantee completeness but serves as a reference for ongoing risk assessment and compliance reporting. It is designed to support technical decision-making without recommending specific vendors or solutions, allowing users to evaluate risks independently based on verified public data.

Vendor: SourceCodester

CVE IDTitleCVSSSeverityPublished
CVE-2025-13421 itsourcecode Human Resource Management System NoticeStore.php sql injection CWE-89 7.3 High2025-11-19
CVE-2025-13420 itsourcecode Human Resource Management System EventStore.php sql injection CWE-89 7.3 High2025-11-19
CVE-2025-40686 Reflected Cross-Site Scripting (XSS) vulnerability in Human Resource Management System CWE-79 6.1AIMediumAI2025-07-29
CVE-2025-40685 Reflected Cross-Site Scripting (XSS) vulnerability in Human Resource Management System CWE-79 6.1AIMediumAI2025-07-29
CVE-2025-40684 Reflected Cross-Site Scripting (XSS) vulnerability in Human Resource Management System CWE-79 6.1AIMediumAI2025-07-29
CVE-2025-40683 Reflected Cross-Site Scripting (XSS) vulnerability in Human Resource Management System CWE-79 6.1AIMediumAI2025-07-29
CVE-2025-40682 SQL injection vulnerability in Human Resource Management System CWE-89 9.8AICriticalAI2025-07-29
CVE-2025-3384 1000 Projects Human Resource Management System employee.php sql injection CWE-89 7.3 High2025-04-07
CVE-2025-2590 code-projects Human Resource Management System recruitment.go UpdateRecruitmentById cross site scripting CWE-79 2.4 Low2025-03-21
CVE-2025-2589 code-projects Human Resource Management System Account.go Index improper authorization CWE-285 5.5 Medium2025-03-21
CVE-2024-13006 1000 Projects Human Resource Management System employeeview.php sql injection CWE-89 7.3 High2024-12-29
CVE-2023-3391 SourceCodester Human Resource Management System detailview.php sql injection CWE-89 6.3 Medium2023-06-23
CVE-2022-4279 SourceCodester Human Resource Management System employeeview.php cross site scripting CWE-707 3.5 Low2022-12-03
CVE-2022-4278 SourceCodester Human Resource Management System employeeadd.php sql injection CWE-707 4.7 Medium2022-12-03
CVE-2022-4273 SourceCodester Human Resource Management System Content-Type employee.php unrestricted upload CWE-266 7.3 High2022-12-03
CVE-2022-3502 Human Resource Management System Leave cross site scripting CWE-707 3.5 Low2022-10-14
CVE-2022-3497 SourceCodester Human Resource Management System Master List cross site scripting CWE-707 3.5 Low2022-10-14
CVE-2022-3496 SourceCodester Human Resource Management System Admin Panel employeeadd.php access control CWE-266 6.3 Medium2022-10-14
CVE-2022-3493 SourceCodester Human Resource Management System Add Employee cross site scripting CWE-707 3.5 Low2022-10-13
CVE-2022-3492 SourceCodester Human Resource Management System Profile Photo os command injection CWE-707 6.3 Medium2022-10-13
CVE-2022-3458 SourceCodester Human Resource Management System Image File employeeview.php unrestricted upload CWE-266 6.3 Medium2022-10-12
CVE-2022-3473 SourceCodester Human Resource Management System getstatecity.php sql injection CWE-707 6.3 Medium2022-10-12
CVE-2022-3472 SourceCodester Human Resource Management System city.php sql injection CWE-707 6.3 Medium2022-10-12
CVE-2022-3471 SourceCodester Human Resource Management System city.php sql injection CWE-707 6.3 Medium2022-10-12
CVE-2022-3470 SourceCodester Human Resource Management System getstatecity.php sql injection CWE-707 6.3 Medium2022-10-12

All 25 known CVE vulnerabilities affecting Human Resource Management System with full Chinese analysis, references, and POCs where available.