Hotel management system
This hub aggregates every CVE we track for Hotel management system, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
40
CVEs tracked
9
Critical
13
High
0
In CISA KEV
Severity distribution
MEDIUM17HIGH13CRITICAL9LOW1
Monthly trend
0
0
0
2
0
0
0
0
1
0
0
0
0
0
0
1
0
0
0
2
0
0
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Hotel management system.
- CVE-2026-7506SourceCodester Hotel Management System check sql injection7.3
- CVE-2026-6142tushar-2223 Hotel Management System roomdelete.php sql injection7.3
- CVE-2025-63949A Reflected Cross-Site Scripting (XSS) vulnerability in yohanawi Hotel Management System (commit 87e004a) allows a remote attacker to execute arbitrary web script via the 'error' parameter in pages...6.1
- CVE-2025-4500code-projects Hotel Management System Edit Room edit stack-based overflow5.3
- CVE-2024-12186code-projects Hotel Management System Available Room hotelnew.c stack-based overflow5.3
- CVE-2024-12185code-projects Hotel Management System Administrator Login Password stack-based overflow5.3
- CVE-2024-42770A Stored Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php" of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via the "us...4.7
- CVE-2024-42776Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.7.2
- CVE-2024-42771A Stored Cross Site Scripting (XSS) vulnerability was found in " /admin/edit_room_controller.php" of the Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary c...4.8
- CVE-2024-42767Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.7.2
- CVE-2024-42772An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to view valid hotel room entries in admin...7.5
- CVE-2024-42769A Reflected Cross Site Scripting (XSS) vulnerability was found in "/core/signup_user.php " of Kashipara Hotel Management System v1.0, which allows remote attackers to execute arbitrary code via "us...6.1
- CVE-2024-42773An Incorrect Access Control vulnerability was found in /admin/edit_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to edit the valid hotel ro...9.1
- CVE-2024-42774An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to delete valid hotel room entries ...7.5
- CVE-2024-42775An Incorrect Access Control vulnerability was found in /admin/add_room_controller.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to add the valid hotel room...9.1
Product normalization is registry-driven with AI assist and human review. How it works