Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SourceCodester — Vulnerabilities & Security Advisories 1985

Browse all 1985 CVE security advisories affecting SourceCodester. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SourceCodester operates as a repository for free and premium source code, scripts, and web applications, primarily serving developers seeking ready-made solutions for rapid deployment. This business model inherently exposes users to significant security risks, as the platform hosts thousands of projects with varying levels of code review. Historically, vulnerabilities found in these downloads frequently include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from outdated frameworks or unpatched dependencies. Privilege escalation flaws are also common, allowing attackers to bypass authentication mechanisms. While SourceCodester does not typically manage post-download security patches, the sheer volume of recorded CVEs highlights systemic issues in code quality assurance. Users relying on these resources must perform rigorous independent security audits, as the platform’s primary focus remains distribution rather than comprehensive vulnerability management or remediation support.

CVE ID Title CVSS Severity Published
CVE-2026-2087 SourceCodester Online Class Record System login.php sql injection — Online Class Record System CWE-89 7.3 High 2026-02-07
CVE-2026-2059 SourceCodester Medical Center Portal Management System emp_edit1.php sql injection — Medical Center Portal Management System CWE-89 7.3 High 2026-02-06
CVE-2026-2057 SourceCodester Medical Center Portal Management System login.php sql injection — Medical Center Portal Management System CWE-89 7.3 High 2026-02-06
CVE-2026-2009 SourceCodester Gas Agency Management System createUser.php access control — Gas Agency Management System CWE-284 6.3 Medium 2026-02-06
CVE-2026-1745 SourceCodester Medical Certificate Generator App cross-site request forgery — Medical Certificate Generator App CWE-352 4.3 Medium 2026-02-02
CVE-2026-1702 SourceCodester Pet Grooming Management Software User Management user.php improper authorization — Pet Grooming Management Software CWE-285 6.3 Medium 2026-01-30
CVE-2026-1154 SourceCodester E-Learning System Lesson index.php cross site scripting — E-Learning System CWE-80 4.3 Medium 2026-01-19
CVE-2026-1148 SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System cross-site request forgery — Patients Waiting Area Queue Management System CWE-352 4.3 Medium 2026-01-19
CVE-2026-1147 SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System api_patient_schedule.php cross site scripting — Patients Waiting Area Queue Management System CWE-79 3.5 Low 2026-01-19
CVE-2026-1146 SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System api_register_patient.php cross site scripting — Patients Waiting Area Queue Management System CWE-79 3.5 Low 2026-01-19
CVE-2026-0580 SourceCodester API Key Manager App Import Key cross site scripting — API Key Manager App CWE-79 3.5 Low 2026-01-05
CVE-2025-14885 SourceCodester Client Database Management System Leads Generation user_leads.php unrestricted upload — Client Database Management System CWE-434 6.3 Medium 2025-12-18
CVE-2025-14530 SourceCodester Real Estate Property Listing App property.php unrestricted upload — Real Estate Property Listing App CWE-434 4.7 Medium 2025-12-11
CVE-2025-14229 SourceCodester Inventory Management System SVC Report Export csv injection — Inventory Management System CWE-1236 4.7 Medium 2025-12-08
CVE-2025-14221 SourceCodester Online Banking System page cross site scripting — Online Banking System CWE-79 3.5 Low 2025-12-08
CVE-2025-14206 SourceCodester Online Student Clearance System Fee Table delete-fee.php improper authorization — Online Student Clearance System CWE-285 6.5 Medium 2025-12-08
CVE-2025-13586 SourceCodester Online Student Clearance System changepassword.php sql injection — Online Student Clearance System CWE-89 4.7 Medium 2025-11-24
CVE-2025-13565 SourceCodester Inventory Management System resetPassword.php password recovery — Inventory Management System CWE-640 5.3 Medium 2025-11-23
CVE-2025-13564 SourceCodester Pre-School Management System FilehelperController.php removefile denial of service — Pre-School Management System CWE-404 5.4 Medium 2025-11-23
CVE-2025-13561 SourceCodester Company Website CMS index.php sql injection — Company Website CMS CWE-89 7.3 High 2025-11-23
CVE-2025-13560 SourceCodester Company Website CMS reset-password.php sql injection — Company Website CMS CWE-89 7.3 High 2025-11-23
CVE-2025-13468 SourceCodester Alumni Management System Delete admin_class.php delete_event authorization — Alumni Management System CWE-862 5.4 Medium 2025-11-20
CVE-2025-13451 SourceCodester Online Shop Project action.php sql injection — Online Shop Project CWE-89 7.3 High 2025-11-20
CVE-2025-13450 SourceCodester Online Shop Project register.php cross site scripting — Online Shop Project CWE-79 3.5 Low 2025-11-20
CVE-2025-13349 SourceCodester Student Grades Management System Add New Grade grades.php cross site scripting — Student Grades Management System CWE-79 3.5 Low 2025-11-18
CVE-2025-13347 SourceCodester Train Station Ticketing System ajax.php sql injection — Train Station Ticketing System CWE-89 6.3 Medium 2025-11-18
CVE-2025-13346 SourceCodester Train Station Ticketing System ajax.php sql injection — Train Station Ticketing System CWE-89 6.3 Medium 2025-11-18
CVE-2025-13345 SourceCodester Train Station Ticketing System ajax.php sql injection — Train Station Ticketing System CWE-89 6.3 Medium 2025-11-18
CVE-2025-13344 SourceCodester Train Station Ticketing System ajax.php sql injection — Train Station Ticketing System CWE-89 7.3 High 2025-11-18
CVE-2025-13343 SourceCodester Interview Management System editQuestion.php cross site scripting — Interview Management System CWE-79 3.5 Low 2025-11-18

This page lists every published CVE security advisory associated with SourceCodester. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.