Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SourceCodester — Vulnerabilities & Security Advisories 1985

Browse all 1985 CVE security advisories affecting SourceCodester. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SourceCodester operates as a repository for free and premium source code, scripts, and web applications, primarily serving developers seeking ready-made solutions for rapid deployment. This business model inherently exposes users to significant security risks, as the platform hosts thousands of projects with varying levels of code review. Historically, vulnerabilities found in these downloads frequently include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from outdated frameworks or unpatched dependencies. Privilege escalation flaws are also common, allowing attackers to bypass authentication mechanisms. While SourceCodester does not typically manage post-download security patches, the sheer volume of recorded CVEs highlights systemic issues in code quality assurance. Users relying on these resources must perform rigorous independent security audits, as the platform’s primary focus remains distribution rather than comprehensive vulnerability management or remediation support.

CVE ID Title CVSS Severity Published
CVE-2026-4777 SourceCodester Sales and Inventory System POST Parameter view_supplier.php sql injection — Sales and Inventory System CWE-89 6.3 Medium 2026-03-24
CVE-2026-4625 SourceCodester Online Admission System programmes.php sql injection — Online Admission System CWE-89 7.3 High 2026-03-24
CVE-2026-4624 SourceCodester Online Library Management System Parameter home.php sql injection — Online Library Management System CWE-89 7.3 High 2026-03-24
CVE-2026-4617 SourceCodester Patients Waiting Area Queue Management System Patient Check-In api_patient_checkin.php ValidateToken improper authorization — Patients Waiting Area Queue Management System CWE-285 7.3 High 2026-03-24
CVE-2026-4615 SourceCodester Online Catering Reservation search.php sql injection — Online Catering Reservation CWE-89 7.3 High 2026-03-23
CVE-2026-4613 SourceCodester E-Commerce Site products.php sql injection — E-Commerce Site CWE-89 7.3 High 2026-03-23
CVE-2026-4574 SourceCodester Simple E-learning System User Profile Update sql injection — Simple E-learning System CWE-89 6.3 Medium 2026-03-23
CVE-2026-4573 SourceCodester Simple E-learning System HTTP GET Parameter delete_post.php sql injection — Simple E-learning System CWE-89 6.3 Medium 2026-03-23
CVE-2026-4572 SourceCodester Sales and Inventory System HTTP POST Request view_product.php sql injection — Sales and Inventory System CWE-89 6.3 Medium 2026-03-23
CVE-2026-4571 SourceCodester Sales and Inventory System HTTP POST Request view_payments.php sql injection — Sales and Inventory System CWE-89 6.3 Medium 2026-03-23
CVE-2026-4570 SourceCodester Sales and Inventory System HTTP POST Request view_customers.php sql injection — Sales and Inventory System CWE-89 6.3 Medium 2026-03-23
CVE-2026-4569 SourceCodester Sales and Inventory System HTTP POST Request view_category.php sql injection — Sales and Inventory System CWE-89 6.3 Medium 2026-03-23
CVE-2026-4568 SourceCodester Sales and Inventory System HTTP GET Request update_supplier.php sql injection — Sales and Inventory System CWE-89 6.3 Medium 2026-03-23
CVE-2026-4013 SourceCodester Web-based Pharmacy Product Management System add_admin.php improper authorization — Web-based Pharmacy Product Management System CWE-285 6.3 Medium 2026-03-12
CVE-2026-3819 SourceCodester Resort Reservation System Reservation Management page cross site scripting — Resort Reservation System CWE-79 3.5 Low 2026-03-09
CVE-2026-3817 SourceCodester Patients Waiting Area Queue Management System patient-search.php improper authorization — Patients Waiting Area Queue Management System CWE-285 5.3 Medium 2026-03-09
CVE-2026-3806 SourceCodester/janobe Resort Reservation System room_rates.php sql injection — Resort Reservation System CWE-89 6.3 Medium 2026-03-09
CVE-2026-3800 SourceCodester/janobe Resort Reservation System controller.php doInsert unrestricted upload — Resort Reservation System CWE-434 6.3 Medium 2026-03-09
CVE-2026-3793 SourceCodester Sales and Inventory System GET Parameter sales_invoice1.php sql injection — Sales and Inventory System CWE-89 6.3 Medium 2026-03-09
CVE-2026-3792 SourceCodester Sales and Inventory System GET Parameter purchase_invoice.php sql injection — Sales and Inventory System CWE-89 6.3 Medium 2026-03-09
CVE-2026-3791 SourceCodester Sales and Inventory System Search dashboard.php sql injection — Sales and Inventory System CWE-89 6.3 Medium 2026-03-09
CVE-2026-3790 SourceCodester Sales and Inventory System POST Parameter check_supplier_details.php sql injection — Sales and Inventory System CWE-89 6.3 Medium 2026-03-09
CVE-2026-3771 SourceCodester/janobe Resort Reservation System accomodation.php sql injection — Resort Reservation System CWE-89 6.3 Medium 2026-03-08
CVE-2026-3770 SourceCodester Computer Laboratory Management System cross-site request forgery — Computer Laboratory Management System CWE-352 4.3 Medium 2026-03-08
CVE-2026-3766 SourceCodester Web-based Pharmacy Product Management System edit-profile.php cross site scripting — Web-based Pharmacy Product Management System CWE-79 3.5 Low 2026-03-08
CVE-2026-3764 SourceCodester Client Database Management System superadmin_user_update.php improper authorization — Client Database Management System CWE-285 7.3 High 2026-03-08
CVE-2026-3762 SourceCodester Client Database Management System Endpoint superadmin_delete_manager.php improper authorization — Client Database Management System CWE-285 7.3 High 2026-03-08
CVE-2026-3761 SourceCodester Client Database Management System Endpoint superadmin_user_delete.php improper authorization — Client Database Management System CWE-285 5.4 Medium 2026-03-08
CVE-2026-3756 SourceCodester Sales and Inventory System check_item_details.php sql injection — Sales and Inventory System CWE-89 6.3 Medium 2026-03-08
CVE-2026-3755 SourceCodester Sales and Inventory System POST check_customer_details.php sql injection — Sales and Inventory System CWE-89 6.3 Medium 2026-03-08

This page lists every published CVE security advisory associated with SourceCodester. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.