Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SourceCodester — Vulnerabilities & Security Advisories 1985

Browse all 1985 CVE security advisories affecting SourceCodester. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SourceCodester operates as a repository for free and premium source code, scripts, and web applications, primarily serving developers seeking ready-made solutions for rapid deployment. This business model inherently exposes users to significant security risks, as the platform hosts thousands of projects with varying levels of code review. Historically, vulnerabilities found in these downloads frequently include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from outdated frameworks or unpatched dependencies. Privilege escalation flaws are also common, allowing attackers to bypass authentication mechanisms. While SourceCodester does not typically manage post-download security patches, the sheer volume of recorded CVEs highlights systemic issues in code quality assurance. Users relying on these resources must perform rigorous independent security audits, as the platform’s primary focus remains distribution rather than comprehensive vulnerability management or remediation support.

CVE ID Title CVSS Severity Published
CVE-2026-92406 SourceCodester Inventory and Monitoring System btn_functions.php add sql injection — Inventory and Monitoring System CWE-89 7.3 High 2026-09-16
CVE-2026-92405 SourceCodester Inventory and Monitoring System index.php sql injection — Inventory and Monitoring System CWE-89 7.3 High 2026-09-16
CVE-2026-92385 SourceCodester Online Food Ordering System Category Update update_category.php cross site scripting — Online Food Ordering System CWE-79 2.4 Low 2026-09-16
CVE-2026-91005 SourceCodester Online Faculty Clearance System Profile Picture Upload edit_picture.php move_uploaded_file unrestricted upload — Online Faculty Clearance System CWE-434 6.3 Medium 2026-09-15
CVE-2026-91004 SourceCodester Online Faculty Clearance System delete_faculty1.php sql injection — Online Faculty Clearance System CWE-89 7.3 High 2026-09-15
CVE-2026-90877 SourceCodester Online Faculty Clearance System update_requirement_status.php sql injection — Online Faculty Clearance System CWE-89 7.3 High 2026-09-15
CVE-2026-90876 SourceCodester Online Faculty Clearance System delete_requirement.php sql injection — Online Faculty Clearance System CWE-89 7.3 High 2026-09-15
CVE-2026-90857 SourceCodester College Notes Gallery Management System Profile Upload userprofile.php unrestricted upload — College Notes Gallery Management System CWE-434 6.3 Medium 2026-09-15
CVE-2026-90856 SourceCodester College Notes Gallery Management System Registration Flow signup.php privileges management — College Notes Gallery Management System CWE-269 7.3 High 2026-09-15
CVE-2026-90855 SourceCodester/katojkalemba Online Food Ordering System order.php sql injection — Online Food Ordering System CWE-89 7.3 High 2026-09-15
CVE-2026-90854 SourceCodester/katojkalemba Online Food Ordering System category-foods.php sql injection — Online Food Ordering System CWE-89 7.3 High 2026-09-15
CVE-2026-90849 SourceCodester College Notes Gallery Management System login.php sql injection — College Notes Gallery Management System CWE-89 7.3 High 2026-09-15
CVE-2026-90697 SourceCodester Inventory Management System invoice.php authorization — Inventory Management System CWE-639 4.3 Medium 2026-09-14
CVE-2026-90696 SourceCodester Inventory Management System Product Management products_handler.php cross site scripting — Inventory Management System CWE-79 3.5 Low 2026-09-14
CVE-2026-90695 SourceCodester Inventory Management System Vendor Management vendors_handler.php cross site scripting — Inventory Management System CWE-79 3.5 Low 2026-09-14
CVE-2026-90694 SourceCodester Inventory Management System Customer Management customers_handler.php cross site scripting — Inventory Management System CWE-79 3.5 Low 2026-09-14
CVE-2026-90615 SourceCodester Class and Exam Timetabling System subject1.php cross site scripting — Class and Exam Timetabling System CWE-79 4.3 Medium 2026-09-14
CVE-2026-90526 SourceCodester School Registration and Fee System save_class.php sql injection — School Registration and Fee System CWE-89 7.3 High 2026-09-13
CVE-2026-90516 SourceCodester School Registration and Fee System pay_report.php sql injection — School Registration and Fee System CWE-89 7.3 High 2026-09-13
CVE-2026-90515 SourceCodester School Registration and Fee System delete_stud.php sql injection — School Registration and Fee System CWE-89 7.3 High 2026-09-13
CVE-2026-90514 SourceCodester School Registration and Fee System save_stud.php sql injection — School Registration and Fee System CWE-89 7.3 High 2026-09-13
CVE-2026-86298 SourceCodester Class and Exam Timetabling System delete_subject.php sql injection — Class and Exam Timetabling System CWE-89 7.3 High 2026-09-07
CVE-2026-86294 SourceCodester Simple Traffic Offense System Settings Update Endpoint save-settings.php cross site scripting — Simple Traffic Offense System CWE-79 4.3 Medium 2026-09-07
CVE-2026-86293 SourceCodester Simple Traffic Offense System Deletion Endpoint delete-user.php missing authentication — Simple Traffic Offense System CWE-306 6.5 Medium 2026-09-07
CVE-2026-86292 SourceCodester Simple Traffic Offense System User Creation saveuser.php missing authentication — Simple Traffic Offense System CWE-306 7.3 High 2026-09-07
CVE-2026-86290 SourceCodester Online Voting System ajax.php save_category sql injection — Online Voting System CWE-89 7.3 High 2026-09-07
CVE-2026-86281 SourceCodester Syllabus-Aligned Learning Management & Examination System cross-site request forgery — Syllabus-Aligned Learning Management & Examination System CWE-352 4.3 Medium 2026-09-07
CVE-2026-86280 SourceCodester Syllabus-Aligned Learning Management & Examination System cict_portal.sql cleartext storage — Syllabus-Aligned Learning Management & Examination System CWE-312 5.3 Medium 2026-09-07
CVE-2026-86279 SourceCodester Syllabus-Aligned Learning Management & Examination System Login auth_process.php session fixiation — Syllabus-Aligned Learning Management & Examination System CWE-384 6.3 Medium 2026-09-07
CVE-2026-86278 SourceCodester Syllabus-Aligned Learning Management & Examination System manage_subjects.php cross site scripting — Syllabus-Aligned Learning Management & Examination System CWE-79 4.3 Medium 2026-09-07

This page lists every published CVE security advisory associated with SourceCodester. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.