Online exam system
This hub aggregates every CVE we track for Online exam system, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
14
CVEs tracked
3
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM10CRITICAL3HIGH1
Monthly trend
0
1
0
0
0
0
1
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 14 most recently published vulnerabilities affecting Online exam system.
- CVE-2025-51567A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access...9.1
- CVE-2025-28087Sourcecodester Online Exam System 1.0 is vulnerable to SQL Injection via dash.php.9.8
- CVE-2024-10353SourceCodester Online Exam System admin-dashboard access control6.3
- CVE-2024-40480A Broken Access Control vulnerability was found in /admin/update.php and /admin/dashboard.php in Kashipara Online Exam System v1.0, which allows remote unauthenticated attackers to view administrat...9.8
- CVE-2024-40478A Stored Cross Site Scripting (XSS) vulnerability was found in "/admin/afeedback.php" in Kashipara Online Exam System v1.0, which allows remote attackers to execute arbitrary code via "rname" and "...5.4
- CVE-2024-40479A SQL injection vulnerability in "/admin/quizquestion.php" in Kashipara Online Exam System v1.0 allows remote attackers to execute arbitrary SQL commands via the "eid" parameter.8.1
- CVE-2023-2771SourceCodester Online Exam System data sql injection6.3
- CVE-2023-2770SourceCodester Online Exam System data sql injection6.3
- CVE-2023-2697SourceCodester Online Exam System POST Parameter data sql injection6.3
- CVE-2023-2696SourceCodester Online Exam System POST Parameter data sql injection6.3
- CVE-2023-2695SourceCodester Online Exam System POST Parameter data sql injection6.3
- CVE-2023-2694SourceCodester Online Exam System POST Parameter data sql injection6.3
- CVE-2023-2693SourceCodester Online Exam System POST Parameter data sql injection6.3
- CVE-2023-2642SourceCodester Online Exam System GET Parameter updateCourse.php sql injection6.3
Product normalization is registry-driven with AI assist and human review. How it works