Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SourceCodester — Vulnerabilities & Security Advisories 1985

Browse all 1985 CVE security advisories affecting SourceCodester. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SourceCodester operates as a repository for free and premium source code, scripts, and web applications, primarily serving developers seeking ready-made solutions for rapid deployment. This business model inherently exposes users to significant security risks, as the platform hosts thousands of projects with varying levels of code review. Historically, vulnerabilities found in these downloads frequently include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from outdated frameworks or unpatched dependencies. Privilege escalation flaws are also common, allowing attackers to bypass authentication mechanisms. While SourceCodester does not typically manage post-download security patches, the sheer volume of recorded CVEs highlights systemic issues in code quality assurance. Users relying on these resources must perform rigorous independent security audits, as the platform’s primary focus remains distribution rather than comprehensive vulnerability management or remediation support.

CVE ID Title CVSS Severity Published
CVE-2026-6189 SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection — Pharmacy Sales and Inventory System CWE-89 7.3 High 2026-04-13
CVE-2026-6188 SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection — Pharmacy Sales and Inventory System CWE-89 7.3 High 2026-04-13
CVE-2026-6187 SourceCodester Pharmacy Sales and Inventory System ajax.php sql injection — Pharmacy Sales and Inventory System CWE-89 7.3 High 2026-04-13
CVE-2026-5812 SourceCodester Pharmacy Product Management System POST Parameter add-sales.php logic error — Pharmacy Product Management System CWE-840 5.4 Medium 2026-04-08
CVE-2026-5811 SourceCodester Online Food Ordering System POST Parameter Actions.php save_product logic error — Online Food Ordering System CWE-840 5.4 Medium 2026-04-08
CVE-2026-5810 SourceCodester Sales and Inventory System GET Parameter delete.php cross site scripting — Sales and Inventory System CWE-79 3.5 Low 2026-04-08
CVE-2026-5576 SourceCodester/jkev Record Management System Add Employee save_emp.php unrestricted upload — Record Management System CWE-434 4.7 Medium 2026-04-05
CVE-2026-5575 SourceCodester/jkev Record Management System Login index.php sql injection — Record Management System CWE-89 7.3 High 2026-04-05
CVE-2026-5531 SourceCodester Student Result Management System HTTP GET Request login_credentials.txt cleartext storage in file — Student Result Management System CWE-313 5.3 Medium 2026-04-05
CVE-2026-5330 SourceCodester/mayuri_k Best Courier Management System User Delete ajax.php access control — Best Courier Management System CWE-284 6.5 Medium 2026-04-02
CVE-2026-5326 SourceCodester Leave Application System User Information index.php authorization — Leave Application System CWE-639 5.3 Medium 2026-04-02
CVE-2026-5325 SourceCodester Simple Customer Relationship Management System Create Ticket create-ticket.php cross site scripting — Simple Customer Relationship Management System CWE-79 3.5 Low 2026-04-02
CVE-2026-5210 SourceCodester Leave Application System file inclusion — Leave Application System CWE-73 7.3 High 2026-03-31
CVE-2026-5209 SourceCodester Leave Application System User Management cross site scripting — Leave Application System CWE-79 2.4 Low 2026-03-31
CVE-2026-5182 SourceCodester Teacher Record System Parameter sql injection — Teacher Record System CWE-89 7.3 High 2026-03-31
CVE-2026-5181 SourceCodester Simple Doctors Appointment System ajax.php unrestricted upload — Simple Doctors Appointment System CWE-434 6.3 Medium 2026-03-31
CVE-2026-5180 SourceCodester Simple Doctors Appointment System ajax.php sql injection — Simple Doctors Appointment System CWE-89 7.3 High 2026-03-31
CVE-2026-5179 SourceCodester Simple Doctors Appointment System login.php sql injection — Simple Doctors Appointment System CWE-89 7.3 High 2026-03-31
CVE-2026-5126 SourceCodester RSS Feed Parser file_get_contents server-side request forgery — RSS Feed Parser CWE-918 6.3 Medium 2026-03-30
CVE-2026-4973 SourceCodester Online Quiz System add-question.php cross site scripting — Online Quiz System CWE-79 3.5 Low 2026-03-27
CVE-2026-4971 SourceCodester Note Taking App cross-site request forgery — Note Taking App CWE-352 4.3 Medium 2026-03-27
CVE-2026-4968 SourceCodester Diary App diary.php cross-site request forgery — Diary App CWE-352 4.3 Medium 2026-03-27
CVE-2026-4839 SourceCodester Food Ordering System Parameter purchase.php sql injection — Food Ordering System CWE-89 7.3 High 2026-03-26
CVE-2026-4838 SourceCodester Malawi Online Market display.php sql injection — Malawi Online Market CWE-89 7.3 High 2026-03-26
CVE-2026-4826 SourceCodester Sales and Inventory System HTTP GET Parameter update_stock.php sql injection — Sales and Inventory System CWE-89 6.3 Medium 2026-03-25
CVE-2026-4825 SourceCodester Sales and Inventory System HTTP GET Parameter update_sales.php sql injection — Sales and Inventory System CWE-89 6.3 Medium 2026-03-25
CVE-2026-4781 SourceCodester Sales and Inventory System HTTP GET Parameter update_purchase.php sql injection — Sales and Inventory System CWE-89 6.3 Medium 2026-03-24
CVE-2026-4780 SourceCodester Sales and Inventory System HTTP GET Parameter update_out_standing.php sql injection — Sales and Inventory System CWE-89 6.3 Medium 2026-03-24
CVE-2026-4779 SourceCodester Sales and Inventory System HTTP GET Parameter update_customer_details.php sql injection — Sales and Inventory System CWE-89 6.3 Medium 2026-03-24
CVE-2026-4778 SourceCodester Sales and Inventory System HTTP GET Parameter update_category.php sql injection — Sales and Inventory System CWE-89 6.3 Medium 2026-03-24

This page lists every published CVE security advisory associated with SourceCodester. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.