CVE-2026-82914
- EPSS 0.25%
- Veröffentlicht 31.08.2026 20:45:36
- Zuletzt bearbeitet 01.09.2026 20:48:22
A security flaw has been discovered in kishan0725 Hospital-Management-System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument Contact results in sql injection. It is possible to launch the attack ...
CVE-2025-69949
- EPSS 0.15%
- Veröffentlicht 29.07.2026 00:00:00
- Zuletzt bearbeitet 01.10.2026 08:10:00
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email.
CVE-2025-69945
- EPSS 0.14%
- Veröffentlicht 29.07.2026 00:00:00
- Zuletzt bearbeitet 05.10.2026 18:10:00
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.
CVE-2025-69944
- EPSS 0.17%
- Veröffentlicht 29.07.2026 00:00:00
- Zuletzt bearbeitet 01.10.2026 08:10:00
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the viewid parameter.
CVE-2025-69943
- EPSS 0.15%
- Veröffentlicht 29.07.2026 00:00:00
- Zuletzt bearbeitet 01.10.2026 08:10:00
kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.
CVE-2025-69942
- EPSS 0.14%
- Veröffentlicht 29.07.2026 00:00:00
- Zuletzt bearbeitet 05.10.2026 18:10:00
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.
CVE-2025-65340
- EPSS 0.14%
- Veröffentlicht 29.07.2026 00:00:00
- Zuletzt bearbeitet 01.10.2026 08:10:00
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.
CVE-2025-63514
- EPSS 0.2%
- Veröffentlicht 18.11.2025 00:00:00
- Zuletzt bearbeitet 20.11.2025 21:54:40
kishan0725 Hospital Management System has a Cross-Site Scripting (XSS) vulnerability in appsearch.php via the email parameter.
CVE-2025-63513
- EPSS 0.27%
- Veröffentlicht 18.11.2025 00:00:00
- Zuletzt bearbeitet 20.11.2025 21:57:49
kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment cancellation functionality.
CVE-2025-63512
- EPSS 0.24%
- Veröffentlicht 18.11.2025 00:00:00
- Zuletzt bearbeitet 20.11.2025 21:58:59
kishan0725 Hospital Management System/ v4 is vulnerable to SQL Injection in admin-panel1.php, specifically in the deleting doctor logic. The application fails to properly sanitize or parameterize user-supplied input from the demail parameter before i...