Hospital Management System [hospital-management] <= 47.0(20-11-2023) (unfixed)
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System allows Upload a Web Shell to a Web Server. This issue affects Hospital Management System: from 47.0(20 through 11.
- Affected:
- up to 47.0(20-11-2023)
- Fix:
- No patched version reported
- Disclosed:
- May 23, 2025
CVE-2025-47663 on NVD →
Hospital Management System [hospital-management] <= 47.0(20-11-2023) (unfixed)
unknown
[en] Incorrect Privilege Assignment vulnerability in mojoomla Hospital Management System allows Privilege Escalation. This issue affects Hospital Management System: from 47.0(20 through 11.
- Affected:
- up to 47.0(20-11-2023)
- Fix:
- No patched version reported
- Disclosed:
- May 23, 2025
CVE-2025-47631 on NVD →
Hospital Management System <= 47.0(20-11-2023) - Authenticated (Subscriber+) Privilege Escalation
high
The Hospital Management System for Wordpress plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 47.0(20-11-2023). This makes it possible for authenticated attackers, with Subscriber-level access and above, to gain administrative-level access.
- CVSS:
- 8.8
- Affected:
- up to 47.0(20-11-2023)
- Fix:
- No patched version reported
- Disclosed:
- May 22, 2025
CVE-2025-47631 on NVD →
Hospital Management System <= 47.0(20-11-2023) - Authenticated (Subscriber+) Arbitrary File Upload
high
The Hospital Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 47.0(20-11-2023). This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on t...
- CVSS:
- 8.8
- Affected:
- up to 47.0(20-11-2023)
- Fix:
- No patched version reported
- Disclosed:
- May 20, 2025
CVE-2025-47663 on NVD →
Hospital Management System [hospital-management] <= 47.0(20-11-2023) (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla Hospital Management System allows SQL Injection.This issue affects Hospital Management System: from n/a through 47.0(20-11-2023).
- Affected:
- up to 47.0(20-11-2023)
- Fix:
- No patched version reported
- Disclosed:
- May 19, 2025
CVE-2025-39357 on NVD →
Hospital Management System [hospital-management] <= 47.0(20-11-2023) (unfixed)
unknown
[en] Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System allows Upload a Web Shell to a Web Server.This issue affects Hospital Management System: from n/a through 47.0(20-11-2023).
- Affected:
- up to 47.0(20-11-2023)
- Fix:
- No patched version reported
- Disclosed:
- May 19, 2025
CVE-2025-39380 on NVD →
Hospital Management System [hospital-management] <= 47.0(20-11-2023) (unfixed)
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla Hospital Management System allows SQL Injection.This issue affects Hospital Management System: from n/a through 47.0(20-11-2023).
- Affected:
- up to 47.0(20-11-2023)
- Fix:
- No patched version reported
- Disclosed:
- May 19, 2025
CVE-2025-39386 on NVD →
Hospital Management System [hospital-management] <= 47.0(20-11-2023) (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla Hospital Management System allows Reflected XSS.This issue affects Hospital Management System: from n/a through 47.0 (20-11-2023).
- Affected:
- up to 47.0(20-11-2023)
- Fix:
- No patched version reported
- Disclosed:
- May 19, 2025
CVE-2025-39393 on NVD →
Hospital Management System <= 47.0(20-11-2023) - Unauthenticated Arbitrary File Upload
critical
The Hospital Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, version 47.0(20-11-2023). This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which...
- CVSS:
- 9.8
- Affected:
- up to 47.0(20-11-2023)
- Fix:
- No patched version reported
- Disclosed:
- Apr 22, 2025
CVE-2025-39380 on NVD →
Hospital Management System <= 47.0(20-11-2023) - Unauthenticated SQL Injection
high
The Hospital Management System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 47.0(20-11-2023) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append...
- CVSS:
- 7.5
- Affected:
- up to 47.0(20-11-2023)
- Fix:
- No patched version reported
- Disclosed:
- Apr 22, 2025
CVE-2025-39386 on NVD →
Hospital Management System <= 47.0(20-11-2023) - Reflected Cross-Site Scripting
medium
The Hospital Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in version * -47.0(20-11-2023) due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...
- CVSS:
- 6.1
- Affected:
- up to 47.0(20-11-2023)
- Fix:
- No patched version reported
- Disclosed:
- Apr 22, 2025
CVE-2025-39393 on NVD →
Hospital Management System <= 47.0(20-11-2023) - Authenticated (Subscriber+) SQL Injection
medium
The Hospital Management System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 47.0(20-11-2023) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscr...
- CVSS:
- 6.5
- Affected:
- up to 47.0(20-11-2023)
- Fix:
- No patched version reported
- Disclosed:
- Apr 21, 2025
CVE-2025-39357 on NVD →
Hospital Management System [hospital-management] <= 100
unknown
[en] Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
- Affected:
- up to 100
- Fixed in:
- 100
- Disclosed:
- Sep 27, 2017
CVE-2017-14846 on NVD →
Mojoomla Hospital Management System for WordPress Theme < 22-05-2018 - SQL Injection
high
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
- CVSS:
- 8.8
- Affected:
- up to 08-03-2018
- Fixed in:
- 22-05-2018
- Disclosed:
- Sep 26, 2017
CVE-2017-14846 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database