📦 Online Bidding System

by Fabian

🔍 What is Online Bidding System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-10841

HIGH CVSS 7.3 Sep 23, 2025

This SQL injection vulnerability in code-projects Online Bidding System 1.0 allows attackers to manipulate database queries through the ID parameter in /administrator/weweee.php. Remote attackers can ...

CVE-2025-10802

HIGH CVSS 7.3 Sep 22, 2025

CVE-2025-10802 is an SQL injection vulnerability in code-projects Online Bidding System 1.0 that allows remote attackers to execute arbitrary SQL commands via the ID parameter in /administrator/remove...

CVE-2025-10795

HIGH CVSS 7.3 Sep 22, 2025

CVE-2025-10795 is an SQL injection vulnerability in code-projects Online Bidding System 1.0 that allows remote attackers to execute arbitrary SQL commands via the ID parameter in /administrator/bidupd...

CVE-2025-10791

HIGH CVSS 7.3 Sep 22, 2025

CVE-2025-10791 is a SQL injection vulnerability in code-projects Online Bidding System 1.0 that allows remote attackers to execute arbitrary SQL commands via the 'aduser' parameter in /administrator/i...

CVE-2025-6471

HIGH CVSS 7.3 Jun 22, 2025

A critical SQL injection vulnerability exists in code-projects Online Bidding System 1.0's administrator interface. Attackers can remotely exploit the 'aduser' parameter to execute arbitrary SQL comma...

CVE-2025-6469

HIGH CVSS 7.3 Jun 22, 2025

CVE-2025-6469 is a critical SQL injection vulnerability in code-projects Online Bidding System 1.0 that allows remote attackers to execute arbitrary SQL commands via the ID parameter in /details.php. ...

CVE-2025-6467

HIGH CVSS 7.3 Jun 22, 2025

CVE-2025-6467 is a critical SQL injection vulnerability in code-projects Online Bidding System 1.0 that allows remote attackers to execute arbitrary SQL commands via the User parameter in /login.php. ...

CVE-2025-13574

MEDIUM CVSS 4.7 Nov 24, 2025

This vulnerability allows remote attackers to upload arbitrary files to the Online Bidding System 1.0 administrator interface via the catimage parameter in the categoryadd function. Attackers can pote...