Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

Online Hospital Management System — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in Online Hospital Management System, with AI-generated Chinese analysis, references, and POCs.

This page documents known weaknesses and security vulnerabilities associated with the Online Hospital Management System developed by various vendors in the healthcare technology sector. It serves as a centralized resource for tracking security flaws identified in this specific class of web-based administrative software used by medical institutions for patient records and scheduling. The collection gathers data from public security advisories, vendor bulletins, and independent research reports covering incidents from 2018 to present. The scope includes critical flaws such as remote code execution, injection attacks, authentication bypasses, and cross-site scripting vulnerabilities that may expose sensitive patient health information or disrupt clinical operations. By aggregating these entries, the page provides a comprehensive view of the security posture of hospital management platforms over time. Users can utilize this resource to track a vendor's advisories and monitor how quickly they respond to reported issues. It allows security professionals to understand the prevalence and impact of specific weakness classes within the healthcare domain, facilitating better risk assessment for their institutions. Additionally, stakeholders can look up a product's vulnerability history to evaluate past security incidents and inform procurement decisions. This historical perspective helps administrators identify trends, such as recurring coding errors or inadequate patch management, that may persist across different versions or similar systems. The information presented is intended to support security audits, compliance reviews, and proactive defense strategies for organizations relying on these critical infrastructure tools.

Vendor: SourceCodester

CVE IDTitleCVSSSeverityPublished
CVE-2026-7632 code-projects Online Hospital Management System viewappointment.php sql injection CWE-89 7.3 High2026-05-02
CVE-2026-7631 code-projects Online Hospital Management System Registration improper authorization CWE-285 5.4 Medium2026-05-02
CVE-2025-9754 Campcodes Online Hospital Management System Edit Profile edit-profile.php cross site scripting CWE-79 3.5 Low2025-09-01
CVE-2025-9753 Campcodes Online Hospital Management System Patient Search patient-search.php cross site scripting CWE-79 2.4 Low2025-09-01
CVE-2025-6408 Campcodes Online Hospital Management System search.php sql injection CWE-89 7.3 High2025-06-21
CVE-2025-6407 Campcodes Online Hospital Management System user-login.php sql injection CWE-89 7.3 High2025-06-21
CVE-2025-6406 Campcodes Online Hospital Management System forgot-password.php sql injection CWE-89 7.3 High2025-06-21
CVE-2025-5365 Campcodes Online Hospital Management System patient-search.php sql injection CWE-89 7.3 High2025-05-31
CVE-2025-5364 Campcodes Online Hospital Management System add-patient.php sql injection CWE-89 7.3 High2025-05-30
CVE-2025-5363 Campcodes Online Hospital Management System index.php sql injection CWE-89 7.3 High2025-05-30
CVE-2025-5362 Campcodes Online Hospital Management System doctor-specilization.php sql injection CWE-89 7.3 High2025-05-30
CVE-2025-5361 Campcodes Online Hospital Management System contact.php sql injection CWE-89 7.3 High2025-05-30
CVE-2025-5360 Campcodes Online Hospital Management System book-appointment.php sql injection CWE-89 7.3 High2025-05-30
CVE-2025-5359 Campcodes Online Hospital Management System appointment-history.php sql injection CWE-89 7.3 High2025-05-30
CVE-2025-5298 Campcodes Online Hospital Management System betweendates-detailsreports.php sql injection CWE-89 7.3 High2025-05-28
CVE-2025-5246 Campcodes Online Hospital Management System query-details.php sql injection CWE-89 7.3 High2025-05-27
CVE-2025-5229 Campcodes Online Hospital Management System view-patient.php sql injection CWE-89 7.3 High2025-05-27
CVE-2025-5224 Campcodes Online Hospital Management System add-doctor.php sql injection CWE-89 7.3 High2025-05-27
CVE-2025-5208 SourceCodester Online Hospital Management System check_availability.php sql injection CWE-89 7.3 High2025-05-26
CVE-2024-5362 SourceCodester Online Hospital Management System departmentDoctor.php sql injection CWE-89 7.3 High2024-05-26
CVE-2023-4185 SourceCodester Online Hospital Management System patientlogin.php sql injection CWE-89 6.3 Medium2023-08-06

All 21 known CVE vulnerabilities affecting Online Hospital Management System with full Chinese analysis, references, and POCs where available.