Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SourceCodester — Vulnerabilities & Security Advisories 1985

Browse all 1985 CVE security advisories affecting SourceCodester. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SourceCodester operates as a repository for free and premium source code, scripts, and web applications, primarily serving developers seeking ready-made solutions for rapid deployment. This business model inherently exposes users to significant security risks, as the platform hosts thousands of projects with varying levels of code review. Historically, vulnerabilities found in these downloads frequently include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from outdated frameworks or unpatched dependencies. Privilege escalation flaws are also common, allowing attackers to bypass authentication mechanisms. While SourceCodester does not typically manage post-download security patches, the sheer volume of recorded CVEs highlights systemic issues in code quality assurance. Users relying on these resources must perform rigorous independent security audits, as the platform’s primary focus remains distribution rather than comprehensive vulnerability management or remediation support.

CVE ID Title CVSS Severity Published
CVE-2024-9321 SourceCodester Online Railway Reservation System view_details.php access control — Online Railway Reservation System CWE-284 5.3 Medium 2024-09-29
CVE-2024-9320 SourceCodester Online Timesheet App Add Timesheet Form add-timesheet.php cross site scripting — Online Timesheet App CWE-79 3.5 Low 2024-09-29
CVE-2024-9319 SourceCodester Online Timesheet App delete-timesheet.php sql injection — Online Timesheet App CWE-89 6.3 Medium 2024-09-28
CVE-2024-9318 SourceCodester Advocate Office Management System activate.php sql injection — Advocate Office Management System CWE-89 6.3 Medium 2024-09-28
CVE-2024-9317 SourceCodester Online Eyewear Shop Master.php delete_category sql injection — Online Eyewear Shop CWE-89 6.3 Medium 2024-09-28
CVE-2024-9315 SourceCodester Employee and Visitor Gate Pass Logging System manage_department.php sql injection — Employee and Visitor Gate Pass Logging System CWE-89 6.3 Medium 2024-09-28
CVE-2024-9300 SourceCodester Online Railway Reservation System Message Us Form contact_us.php cross site scripting — Online Railway Reservation System CWE-79 4.3 Medium 2024-09-28
CVE-2024-9299 SourceCodester Online Railway Reservation System ?page=reserve cross site scripting — Online Railway Reservation System CWE-79 3.5 Low 2024-09-28
CVE-2024-9298 SourceCodester Online Railway Reservation System Ticket ?page=tickets access control — Online Railway Reservation System CWE-284 4.3 Medium 2024-09-28
CVE-2024-9297 SourceCodester Online Railway Reservation System admin improper authorization — Online Railway Reservation System CWE-285 6.3 Medium 2024-09-28
CVE-2024-9296 SourceCodester Advocate Office Management System forgot_pass.php sql injection — Advocate Office Management System CWE-89 7.3 High 2024-09-28
CVE-2024-9295 SourceCodester Advocate Office Management System login.php sql injection — Advocate Office Management System CWE-89 7.3 High 2024-09-28
CVE-2024-9093 SourceCodester Profile Registration without Reload Refresh GET Parameter del.php sql injection — Profile Registration without Reload Refresh CWE-89 6.3 Medium 2024-09-23
CVE-2024-9092 SourceCodester Profile Registration without Reload Refresh Registration Form add.php cross site scripting — Profile Registration without Reload Refresh CWE-79 3.5 Low 2024-09-23
CVE-2024-9090 SourceCodester Modern Loan Management System search_member.php sql injection — Modern Loan Management System CWE-89 6.3 Medium 2024-09-22
CVE-2024-9089 SourceCodester Modern Loan Management System update_loan_record.php cross site scripting — Modern Loan Management System CWE-79 3.5 Low 2024-09-22
CVE-2024-9088 SourceCodester Telecom Billing Management System login buffer overflow — Telecom Billing Management System CWE-120 6.3 Medium 2024-09-22
CVE-2024-9083 SourceCodester Employee Management System add-admin.php cross site scripting — Employee Management System CWE-79 2.4 Low 2024-09-22
CVE-2024-9082 SourceCodester Online Eyewear Shop User Creation Users.php improper authorization — Online Eyewear Shop CWE-285 6.3 Medium 2024-09-22
CVE-2024-9081 SourceCodester Online Eyewear Shop view_category.php sql injection — Online Eyewear Shop CWE-89 6.3 Medium 2024-09-22
CVE-2024-9041 SourceCodester Best House Rental Management System ajax.php sql injection — Best House Rental Management System CWE-89 6.3 Medium 2024-09-20
CVE-2024-9039 SourceCodester Best House Rental Management System ajax.php sql injection — Best House Rental Management System CWE-89 7.3 High 2024-09-20
CVE-2024-9033 SourceCodester Best House Rental Management System ajax.php cross site scripting — Best House Rental Management System CWE-79 3.5 Low 2024-09-20
CVE-2024-9032 SourceCodester Simple Forum-Discussion System index.php path traversal — Simple Forum-Discussion System CWE-22 6.3 Medium 2024-09-20
CVE-2024-9008 SourceCodester Best Online News Portal Comment Section news-details.php sql injection — Best Online News Portal CWE-89 6.3 Medium 2024-09-19
CVE-2024-8951 SourceCodester Resort Reservation System manage_fee.php cross site scripting — Resort Reservation System CWE-79 3.5 Low 2024-09-17
CVE-2024-8949 SourceCodester Online Eyewear Shop Cart Content Master.php improper ownership management — Online Eyewear Shop CWE-282 6.3 Medium 2024-09-17
CVE-2024-8711 SourceCodester Food Ordering Management System includes exposure of information through directory listing — Food Ordering Management System CWE-548 5.3 Medium 2024-09-12
CVE-2024-8709 SourceCodester Best House Rental Management System admin_class.php save_user sql injection — Best House Rental Management System CWE-89 6.3 Medium 2024-09-12
CVE-2024-8708 SourceCodester Best House Rental Management System categories.php cross site scripting — Best House Rental Management System CWE-79 3.5 Low 2024-09-12

This page lists every published CVE security advisory associated with SourceCodester. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.