Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SourceCodester — Vulnerabilities & Security Advisories 1985

Browse all 1985 CVE security advisories affecting SourceCodester. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SourceCodester operates as a repository for free and premium source code, scripts, and web applications, primarily serving developers seeking ready-made solutions for rapid deployment. This business model inherently exposes users to significant security risks, as the platform hosts thousands of projects with varying levels of code review. Historically, vulnerabilities found in these downloads frequently include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from outdated frameworks or unpatched dependencies. Privilege escalation flaws are also common, allowing attackers to bypass authentication mechanisms. While SourceCodester does not typically manage post-download security patches, the sheer volume of recorded CVEs highlights systemic issues in code quality assurance. Users relying on these resources must perform rigorous independent security audits, as the platform’s primary focus remains distribution rather than comprehensive vulnerability management or remediation support.

CVE ID Title CVSS Severity Published
CVE-2025-4547 SourceCodester Web-based Pharmacy Product Management System Add User Page cross site scripting — Web-based Pharmacy Product Management System CWE-79 2.4 Low 2025-05-11
CVE-2025-4504 SourceCodester Online College Library System index.php sql injection — Online College Library System CWE-89 7.3 High 2025-05-10
CVE-2025-4481 SourceCodester Apartment Visitor Management System search-result.php sql injection — Apartment Visitor Management System CWE-89 7.3 High 2025-05-09
CVE-2025-4470 SourceCodester Online Student Clearance System add-student.php cross site scripting — Online Student Clearance System CWE-79 2.4 Low 2025-05-09
CVE-2025-4469 SourceCodester Online Student Clearance System add-admin.php cross site scripting — Online Student Clearance System CWE-79 2.4 Low 2025-05-09
CVE-2025-4468 SourceCodester Online Student Clearance System edit-photo.php unrestricted upload — Online Student Clearance System CWE-434 7.3 High 2025-05-09
CVE-2025-4467 SourceCodester Online Student Clearance System edit-admin.php sql injection — Online Student Clearance System CWE-89 7.3 High 2025-05-09
CVE-2025-4331 SourceCodester Online Student Clearance System login.php sql injection — Online Student Clearance System CWE-89 7.3 High 2025-05-06
CVE-2025-4314 SourceCodester Advanced Web Store index.php sql injection — Advanced Web Store CWE-89 7.3 High 2025-05-06
CVE-2025-4313 SourceCodester Advanced Web Store admin_addnew_product.php sql injection — Advanced Web Store CWE-89 7.3 High 2025-05-06
CVE-2025-4312 SourceCodester Advanced Web Store productdetail.php sql injection — Advanced Web Store CWE-89 7.3 High 2025-05-06
CVE-2025-4283 SourceCodester/oretnom23 Stock Management System Login.php sql injection — Stock Management System CWE-89 7.3 High 2025-05-05
CVE-2025-4282 SourceCodester/oretnom23 Stock Management System Users.php cross-site request forgery — Stock Management System CWE-352 4.3 Medium 2025-05-05
CVE-2025-4267 SourceCodester/oretnom23 Stock Management System Purchase Order Details Page view_po sql injection — Stock Management System CWE-89 4.7 Medium 2025-05-05
CVE-2025-4248 SourceCodester Simple To-Do List System complete_task.php sql injection — Simple To-Do List System CWE-89 6.3 Medium 2025-05-04
CVE-2025-4247 SourceCodester Simple To-Do List System delete_task.php sql injection — Simple To-Do List System CWE-89 6.3 Medium 2025-05-04
CVE-2025-4196 SourceCodester Patient Record Management System birthing.php sql injection — Patient Record Management System CWE-89 6.3 Medium 2025-05-02
CVE-2025-4173 SourceCodester Online Eyewear Shop Master.php delete_cart sql injection — Online Eyewear Shop CWE-89 6.3 Medium 2025-05-01
CVE-2025-3826 SourceCodester Web-based Pharmacy Product Management System add-supplier.php cross site scripting — Web-based Pharmacy Product Management System CWE-79 2.4 Low 2025-04-20
CVE-2025-3825 SourceCodester Web-based Pharmacy Product Management System add-category.php cross site scripting — Web-based Pharmacy Product Management System CWE-79 2.4 Low 2025-04-20
CVE-2025-3824 SourceCodester Web-based Pharmacy Product Management System add-product.php cross site scripting — Web-based Pharmacy Product Management System CWE-79 2.4 Low 2025-04-20
CVE-2025-3823 SourceCodester Web-based Pharmacy Product Management System add-stock.php cross site scripting — Web-based Pharmacy Product Management System CWE-79 2.4 Low 2025-04-20
CVE-2025-3822 SourceCodester Web-based Pharmacy Product Management System changepassword.php cross site scripting — Web-based Pharmacy Product Management System CWE-79 2.4 Low 2025-04-20
CVE-2025-3821 SourceCodester Web-based Pharmacy Product Management System add-admin.php cross site scripting — Web-based Pharmacy Product Management System CWE-79 2.4 Low 2025-04-20
CVE-2025-3817 SourceCodester Online Eyewear Shop Master.php sql injection — Online Eyewear Shop CWE-89 6.3 Medium 2025-04-19
CVE-2025-3783 SourceCodester Web-based Pharmacy Product Management System add-product.php unrestricted upload — Web-based Pharmacy Product Management System CWE-434 6.3 Medium 2025-04-18
CVE-2025-3765 SourceCodester Web-based Pharmacy Product Management System edit-photo.php unrestricted upload — Web-based Pharmacy Product Management System CWE-434 6.3 Medium 2025-04-17
CVE-2025-3764 SourceCodester Web-based Pharmacy Product Management System edit-product.php unrestricted upload — Web-based Pharmacy Product Management System CWE-434 6.3 Medium 2025-04-17
CVE-2025-3763 SourceCodester Phone Management System Password main buffer overflow — Phone Management System CWE-120 5.3 Medium 2025-04-17
CVE-2025-3729 SourceCodester Web-based Pharmacy Product Management System Database Backup backup.php os command injection — Web-based Pharmacy Product Management System CWE-78 7.3 High 2025-04-16

This page lists every published CVE security advisory associated with SourceCodester. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.