📦 Grocery Sales And Inventory System

by Campcodes

🔍 What is Grocery Sales And Inventory System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-10786

HIGH CVSS 7.3 Sep 22, 2025

This SQL injection vulnerability in Campcodes Grocery Sales and Inventory System 1.0 allows attackers to execute arbitrary SQL commands via the ID parameter in the /ajax.php?action=delete_user endpoin...

CVE-2025-10565

HIGH CVSS 7.3 Sep 16, 2025

Campcodes Grocery Sales and Inventory System 1.0 contains a SQL injection vulnerability in the /ajax.php?action=delete_receiving endpoint via manipulation of the ID parameter. This allows remote attac...

CVE-2025-10562

HIGH CVSS 7.3 Sep 16, 2025

This vulnerability allows remote attackers to execute arbitrary SQL commands via the ID parameter in the /ajax.php?action=save_product endpoint in Campcodes Grocery Sales and Inventory System 1.0. Thi...

CVE-2025-10416

HIGH CVSS 7.3 Sep 15, 2025

This vulnerability allows remote attackers to execute arbitrary SQL commands via the ID parameter in the /ajax.php?action=delete_supplier endpoint in Campcodes Grocery Sales and Inventory System 1.0. ...

CVE-2025-10415

HIGH CVSS 7.3 Sep 14, 2025

Campcodes Grocery Sales and Inventory System 1.0 contains a SQL injection vulnerability in the /ajax.php?action=save_supplier endpoint via manipulation of the ID parameter. This allows remote attacker...

CVE-2025-10413

HIGH CVSS 7.3 Sep 14, 2025

This vulnerability allows remote attackers to execute SQL injection attacks against Campcodes Grocery Sales and Inventory System 1.0 via the /ajax.php?action=delete_customer endpoint. Attackers can ma...

CVE-2025-10030

HIGH CVSS 7.3 Sep 6, 2025

CVE-2025-10030 is a SQL injection vulnerability in Campcodes Grocery Sales and Inventory System 1.0 that allows remote attackers to execute arbitrary SQL commands via the ID parameter in the /ajax.php...

CVE-2025-10032

MEDIUM CVSS 4.3 Sep 6, 2025

This vulnerability in Campcodes Grocery Sales and Inventory System 1.0 allows attackers to inject malicious scripts via the 'page' parameter in /index.php, leading to cross-site scripting (XSS). Attac...