This page lists publicly disclosed CVE vulnerabilities affecting oretnom23 banking_system (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2025-14221 | A vulnerability was detected in SourceCodester Online Banking System 1.0. This impacts an unknown function of the file /?page=user. The manipulation of the argument First Name/Last Name results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used. | [email protected] | 2.0 | 0.21% | 2025-12-08 | 2026-04-29 |
| CVE-2022-26646 | Online Banking System Protect v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the pages parameter. | [email protected] | 9.8 | 1.27% | 2022-03-30 | 2025-12-16 |
| CVE-2022-26645 | A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function. | [email protected] | 9.8 | 2.55% | 2022-03-30 | 2025-12-16 |
| CVE-2022-26644 | Online Banking System Protect v1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via parameters on user profile, system_info and accounts management. | [email protected] | 6.1 | 0.62% | 2022-03-30 | 2025-12-16 |
| CVE-2021-41659 | SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username or password field. | [email protected] | 9.8 | 1.25% | 2022-01-24 | 2025-12-16 |