Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SourceCodester — Vulnerabilities & Security Advisories 1985

Browse all 1985 CVE security advisories affecting SourceCodester. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SourceCodester operates as a repository for free and premium source code, scripts, and web applications, primarily serving developers seeking ready-made solutions for rapid deployment. This business model inherently exposes users to significant security risks, as the platform hosts thousands of projects with varying levels of code review. Historically, vulnerabilities found in these downloads frequently include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from outdated frameworks or unpatched dependencies. Privilege escalation flaws are also common, allowing attackers to bypass authentication mechanisms. While SourceCodester does not typically manage post-download security patches, the sheer volume of recorded CVEs highlights systemic issues in code quality assurance. Users relying on these resources must perform rigorous independent security audits, as the platform’s primary focus remains distribution rather than comprehensive vulnerability management or remediation support.

CVE ID Title CVSS Severity Published
CVE-2025-8470 SourceCodester Online Hotel Reservation System deleteroom.php sql injection — Online Hotel Reservation System CWE-89 7.3 High 2025-08-02
CVE-2025-8469 SourceCodester Online Hotel Reservation System deletegallery.php sql injection — Online Hotel Reservation System CWE-89 7.3 High 2025-08-02
CVE-2025-7408 SourceCodester Zoo Management System animal_form_template.php cross site scripting — Zoo Management System CWE-79 3.5 Low 2025-07-10
CVE-2025-7144 SourceCodester Best Salon Management System Admin Profile Page admin-profile.php cross site scripting — Best Salon Management System CWE-79 2.4 Low 2025-07-07
CVE-2025-7143 SourceCodester Best Salon Management System Update Tax Page edit-tax.php cross site scripting — Best Salon Management System CWE-79 2.4 Low 2025-07-07
CVE-2025-7142 SourceCodester Best Salon Management System search-appointment.php cross site scripting — Best Salon Management System CWE-79 2.4 Low 2025-07-07
CVE-2025-7141 SourceCodester Best Salon Management System Update Staff Page edit_plan.php cross site scripting — Best Salon Management System CWE-79 2.4 Low 2025-07-07
CVE-2025-7140 SourceCodester Best Salon Management System Update Staff Page edit-staff.php cross site scripting — Best Salon Management System CWE-79 2.4 Low 2025-07-07
CVE-2025-7139 SourceCodester Best Salon Management System Update Customer Details Page edit-customer-detailed.php cross site scripting — Best Salon Management System CWE-79 2.4 Low 2025-07-07
CVE-2025-7138 SourceCodester Best Salon Management System admin-profile.php sql injection — Best Salon Management System CWE-89 6.3 Medium 2025-07-07
CVE-2025-7137 SourceCodester Best Salon Management System schedule-staff.php sql injection — Best Salon Management System CWE-89 6.3 Medium 2025-07-07
CVE-2025-6880 SourceCodester Best Salon Management System edit-tax.php sql injection — Best Salon Management System CWE-89 6.3 Medium 2025-06-30
CVE-2025-6879 SourceCodester Best Salon Management System add-tax.php sql injection — Best Salon Management System CWE-89 6.3 Medium 2025-06-30
CVE-2025-6878 SourceCodester Best Salon Management System search-appointment.php sql injection — Best Salon Management System CWE-89 6.3 Medium 2025-06-30
CVE-2025-6877 SourceCodester Best Salon Management System edit-category.php sql injection — Best Salon Management System CWE-89 6.3 Medium 2025-06-29
CVE-2025-6876 SourceCodester Best Salon Management System add-category.php sql injection — Best Salon Management System CWE-89 6.3 Medium 2025-06-29
CVE-2025-6875 SourceCodester Best Salon Management System edit-subscription.php sql injection — Best Salon Management System CWE-89 6.3 Medium 2025-06-29
CVE-2025-6874 SourceCodester Best Salon Management System add_subscribe.php sql injection — Best Salon Management System CWE-89 6.3 Medium 2025-06-29
CVE-2025-6873 SourceCodester Simple Company Website Users.php unrestricted upload — Simple Company Website CWE-434 4.7 Medium 2025-06-29
CVE-2025-6872 SourceCodester Simple Company Website SystemSettings.php unrestricted upload — Simple Company Website CWE-434 4.7 Medium 2025-06-29
CVE-2025-6871 SourceCodester Simple Company Website Login.php sql injection — Simple Company Website CWE-89 7.3 High 2025-06-29
CVE-2025-6870 SourceCodester Simple Company Website Content.php unrestricted upload — Simple Company Website CWE-434 4.7 Medium 2025-06-29
CVE-2025-6869 SourceCodester Simple Company Website manage.php sql injection — Simple Company Website CWE-89 4.7 Medium 2025-06-29
CVE-2025-6868 SourceCodester Simple Company Website manage.php sql injection — Simple Company Website CWE-89 4.7 Medium 2025-06-29
CVE-2025-6867 SourceCodester Simple Company Website manage.php sql injection — Simple Company Website CWE-89 4.7 Medium 2025-06-29
CVE-2025-6862 SourceCodester Best Salon Management System edit_plan.php sql injection — Best Salon Management System CWE-89 6.3 Medium 2025-06-29
CVE-2025-6861 SourceCodester Best Salon Management System add_plan.php sql injection — Best Salon Management System CWE-89 6.3 Medium 2025-06-29
CVE-2025-6860 SourceCodester Best Salon Management System staff_commision.php sql injection — Best Salon Management System CWE-89 6.3 Medium 2025-06-29
CVE-2025-6859 SourceCodester Best Salon Management System pro_sale.php sql injection — Best Salon Management System CWE-89 6.3 Medium 2025-06-29
CVE-2025-6609 SourceCodester Best Salon Management System bwdates-reports-details.php sql injection — Best Salon Management System CWE-89 6.3 Medium 2025-06-25

This page lists every published CVE security advisory associated with SourceCodester. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.