← Back

Egavilanmedia

egavilanmedia

14 CVEs • 8 products

Products (8)

Click to collapse
Toggle

CVEs (14)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Egavilanmedia
1Expense Management System
Jun 17, 2026
Jun 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
EGavilan Media Expense-Management-System 1.0 is vulnerable to SQL Injection via /expense_action.php. This allows a remote attacker to compromise Application SQL database.
1Egavilanmedia
1User Registration And Login System With Admin Panel
Jun 17, 2026
Jun 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise Application SQL database.
1Egavilanmedia
1Phpcrud
Jun 17, 2026
Jan 28, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored Cross Site Scripting (XSS) vulnerability in EGavilan Media CRUD Operation with PHP, MySQL, Bootstrap, and Dompdf via First Name or Last Name parameter in the 'Add New Record Feature'.
1Egavilanmedia
1User Registration And Login System With Admin Panel
Jun 17, 2026
Jan 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.
1Egavilanmedia
1User Registration And Login System With Admin Panel
Jun 17, 2026
Dec 30, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page. This vulnerability can result in the attacker injecting the XSS payload in Admin...Show more
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Profile Page. This vulnerability can result in the attacker injecting the XSS payload in Admin Full Name and each time admin visits the Profile page from the admin panel, the XSS triggers.Show less
1Egavilanmedia
1User Registration And Login System With Admin Panel
Jun 17, 2026
Dec 30, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab using the Full Name of the user. This vulnerability can result in the a...Show more
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by cross-site scripting (XSS) in the Admin Panel - Manage User tab using the Full Name of the user. This vulnerability can result in the attacker injecting the XSS payload in the User Registration section and each time admin visits the manage user section from the admin panel, the XSS triggers and the attacker can steal the cookie according to the crafted payload.Show less
1Egavilanmedia
1User Registration And Login System With Admin Panel
Jun 17, 2026
Dec 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.
1Egavilanmedia
1Egm Address Book
Jun 17, 2026
Dec 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
EGavilan Media EGM Address Book 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
1Egavilanmedia
1Under Construction Page With Cpanel
Jun 17, 2026
Dec 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
EGavilan Media Under Construction page with cPanel 1.0 contains a SQL injection vulnerability. An attacker can gain Admin Panel access using malicious SQL injection queries to perform remote arbitrary code execution.
1Egavilanmedia
1User Registration And Login System With Admin Panel
Jun 17, 2026
Dec 23, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability via the 'Full Name' parameter in the User Registration section of User Registration & Login System with Admin Panel 1.0.
1Egavilanmedia
1Ecm Address Book
Jun 17, 2026
Dec 21, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
EgavilanMedia ECM Address Book 1.0 is affected by SQL injection. An attacker can bypass the Admin Login panel through SQLi and get Admin access and add or remove any user.
1Egavilanmedia
1User Registration & Login System With Admin Panel
Jun 17, 2026
Dec 21, 2020
N/A· v4
8.0 HIGH· v3
6.0 MEDIUM· v2
EgavilanMedia User Registration & Login System with Admin Panel 1.0 is affected by Cross Site Request Forgery (CSRF) to remotely gain privileges in the User Profile panel. An attacker can update any user's account.
1Egavilanmedia
1Barcodes Generator
Jun 17, 2026
Dec 15, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
EGavilan Barcodes generator 1.0 is affected by: Cross Site Scripting (XSS) via the index.php. An Attacker is able to inject the XSS payload in the web application each time a user visits the website.
1Egavilanmedia
1Expense Management System
Jun 17, 2026
Dec 15, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
XSS in the Add Expense Component of EGavilan Media Expense Management System 1.0 allows an attacker to permanently store malicious JavaScript code via the 'description' field