Lost and found information system
This hub aggregates every CVE we track for Lost and found information system, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
27
CVEs tracked
3
Critical
3
High
0
In CISA KEV
Severity distribution
MEDIUM18LOW3HIGH3CRITICAL3
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Lost and found information system.
- CVE-2024-37859Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the page parameter to php-lfis/admin/index.php.6.1
- CVE-2024-37856Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the first, last, middle name fields in the User Profile page.5.4
- CVE-2024-37858SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the id parameter to php-lfis/admin/categories/manage_category.php.9.8
- CVE-2024-37857SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via id parameter to php-lfis/admin/categories/view_category.php.8.8
- CVE-2023-33676Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*" which can be escalated to the remote command execution.8.4
- CVE-2023-33677Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*".7.5
- CVE-2023-38965Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.9.8
- CVE-2023-5018SourceCodester Lost and Found Information System POST Parameter sql injection6.3
- CVE-2023-36159Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers to run arbitrary code via the First Name, Middle Name and Last Name fields o...6.1
- CVE-2023-3850SourceCodester Lost and Found Information System HTTP POST Request sql injection6.3
- CVE-2023-3680SourceCodester Lost and Found Information System HTTP POST Request sql injection6.3
- CVE-2023-3679SourceCodester Lost and Found Information System HTTP POST Request sql injection6.3
- CVE-2023-33592Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information.9.8
- CVE-2023-3177SourceCodester Lost and Found Information System view_inquiry.php sql injection6.3
- CVE-2023-3176SourceCodester Lost and Found Information System manage_user.php sql injection6.3
Product normalization is registry-driven with AI assist and human review. How it works