Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

projectworlds — Vulnerabilities & Security Advisories 105

Browse all 105 CVE security advisories affecting projectworlds. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Projectworlds operates as a provider of enterprise resource planning and business management software, primarily targeting small to medium-sized enterprises for inventory, sales, and accounting automation. Security audits have identified a significant volume of vulnerabilities, with 101 Common Vulnerabilities and Exposures currently documented. The most prevalent issues involve remote code execution and cross-site scripting, often stemming from inadequate input validation in web interfaces. Additionally, the platform has historically suffered from broken access control flaws, allowing unauthorized privilege escalation and data exposure. These weaknesses suggest systemic gaps in secure coding practices and rigorous penetration testing protocols. While no single catastrophic breach has been widely publicized, the high count of active CVEs indicates persistent exposure to automated exploitation tools. Organizations relying on this software must prioritize immediate patching and network segmentation to mitigate the risk of compromise, given the consistent pattern of critical severity ratings in recent disclosures.

CVE ID Title CVSS Severity Published
CVE-2025-13254 projectworlds Advanced Library Management System add_member.php sql injection — Advanced Library Management System CWE-89 6.3 Medium 2025-11-17
CVE-2025-13253 projectworlds Advanced Library Management System add_librarian.php sql injection — Advanced Library Management System CWE-89 6.3 Medium 2025-11-16
CVE-2025-12938 projectworlds Online Admission System process_login.php sql injection — Online Admission System CWE-89 7.3 High 2025-11-10
CVE-2025-12862 projectworlds Online Notes Sharing Platform userprofile.php unrestricted upload — Online Notes Sharing Platform CWE-434 6.3 Medium 2025-11-07
CVE-2025-12237 projectworlds Advanced Library Management System index.php sql injection — Advanced Library Management System CWE-89 7.3 High 2025-10-27
CVE-2025-12231 projectworlds Expense Management System Expense Categories create cross site scripting — Expense Management System CWE-79 2.4 Low 2025-10-27
CVE-2025-12230 projectworlds Expense Management System Currency create cross site scripting — Expense Management System CWE-79 2.4 Low 2025-10-27
CVE-2025-12229 projectworlds Expense Management System Roles Page create cross site scripting — Expense Management System CWE-79 2.4 Low 2025-10-27
CVE-2025-12228 projectworlds Expense Management System Users Page create cross site scripting — Expense Management System CWE-79 2.4 Low 2025-10-27
CVE-2025-12227 projectworlds Gate Pass Management System add-pass.php cross site scripting — Gate Pass Management System CWE-79 3.5 Low 2025-10-27
CVE-2025-12215 projectworlds Online Shopping System login_submit.php sql injection — Online Shopping System CWE-89 7.3 High 2025-10-27
CVE-2025-11604 projectworlds Online Ordering Food System all-orders.php sql injection — Online Ordering Food System CWE-89 7.3 High 2025-10-11
CVE-2025-11557 projectworlds Gate Pass Management System add-pass.php sql injection — Gate Pass Management System CWE-89 7.3 High 2025-10-09
CVE-2025-11475 projectworlds Advanced Library Management System view_member.php sql injection — Advanced Library Management System CWE-89 7.3 High 2025-10-08
CVE-2025-11426 projectworlds Advanced Library Management System edit_book.php unrestricted upload — Advanced Library Management System CWE-434 6.3 Medium 2025-10-08
CVE-2025-11425 projectworlds Advanced Library Management System edit_admin.php cross site scripting — Advanced Library Management System CWE-79 2.4 Low 2025-10-08
CVE-2025-11103 Projectworlds Online Tours and Travels change-image.php unrestricted upload — Online Tours and Travels CWE-434 4.7 Medium 2025-09-28
CVE-2025-11070 Projectworlds Online Shopping System cart_add.php sql injection — Online Shopping System CWE-89 7.3 High 2025-09-27
CVE-2025-11067 Projectworlds Visitor Management System Add Visitor myform.php cross site scripting — Visitor Management System CWE-79 2.4 Low 2025-09-27
CVE-2025-9928 projectworlds Travel Management System viewcategory.php sql injection — Travel Management System CWE-89 7.3 High 2025-09-03
CVE-2025-9927 projectworlds Travel Management System viewpackage.php sql injection — Travel Management System CWE-89 7.3 High 2025-09-03
CVE-2025-9926 projectworlds Travel Management System viewsubcategory.php sql injection — Travel Management System CWE-89 7.3 High 2025-09-03
CVE-2025-9925 projectworlds Travel Management System detail.php sql injection — Travel Management System CWE-89 7.3 High 2025-09-03
CVE-2025-9924 projectworlds Travel Management System enquiry.php sql injection — Travel Management System CWE-89 7.3 High 2025-09-03
CVE-2025-9053 projectworlds Travel Management System updatesubcategory.php sql injection — Travel Management System CWE-89 7.3 High 2025-08-15
CVE-2025-9052 projectworlds Travel Management System updatepackage.php sql injection — Travel Management System CWE-89 7.3 High 2025-08-15
CVE-2025-9051 projectworlds Travel Management System updatecategory.php sql injection — Travel Management System CWE-89 7.3 High 2025-08-15
CVE-2025-9050 projectworlds Travel Management System addcategory.php sql injection — Travel Management System CWE-89 7.3 High 2025-08-15
CVE-2025-9047 projectworlds Visitor Management System visitor_out.php sql injection — Visitor Management System CWE-89 7.3 High 2025-08-15
CVE-2025-8948 projectworlds Visitor Management System front.php sql injection — Visitor Management System CWE-89 7.3 High 2025-08-14

This page lists every published CVE security advisory associated with projectworlds. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.