Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SourceCodester — Vulnerabilities & Security Advisories 1985

Browse all 1985 CVE security advisories affecting SourceCodester. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SourceCodester operates as a repository for free and premium source code, scripts, and web applications, primarily serving developers seeking ready-made solutions for rapid deployment. This business model inherently exposes users to significant security risks, as the platform hosts thousands of projects with varying levels of code review. Historically, vulnerabilities found in these downloads frequently include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from outdated frameworks or unpatched dependencies. Privilege escalation flaws are also common, allowing attackers to bypass authentication mechanisms. While SourceCodester does not typically manage post-download security patches, the sheer volume of recorded CVEs highlights systemic issues in code quality assurance. Users relying on these resources must perform rigorous independent security audits, as the platform’s primary focus remains distribution rather than comprehensive vulnerability management or remediation support.

CVE ID Title CVSS Severity Published
CVE-2024-8610 SourceCodester Best House Rental Management System New Tenant Page index.php cross site scripting — Best House Rental Management System CWE-79 3.5 Low 2024-09-09
CVE-2024-8604 SourceCodester Online Food Ordering System Create an Account Page index.php cross site scripting — Online Food Ordering System CWE-79 4.3 Medium 2024-09-09
CVE-2024-8583 SourceCodester Online Bank Management System Feedback mfeedback.php cross site scripting — Online Bank Management System CWE-79 3.5 Low 2024-09-08
CVE-2024-8582 SourceCodester Food Ordering Management System index.php cross site scripting — Food Ordering Management System CWE-79 3.5 Low 2024-09-08
CVE-2024-8564 SourceCodester PHP CRUD update.php sql injection — PHP CRUD CWE-89 6.3 Medium 2024-09-07
CVE-2024-8563 SourceCodester PHP CRUD update.php cross site scripting — PHP CRUD CWE-79 3.5 Low 2024-09-07
CVE-2024-8562 SourceCodester PHP CRUD Add.php cross site scripting — PHP CRUD CWE-79 3.5 Low 2024-09-07
CVE-2024-8561 SourceCodester PHP CRUD Delete Person delete.php sql injection — PHP CRUD CWE-89 6.3 Medium 2024-09-07
CVE-2024-8560 SourceCodester Simple Invoice Generator System save_invoice.php sql injection — Simple Invoice Generator System CWE-89 6.3 Medium 2024-09-07
CVE-2024-8559 SourceCodester Online Food Menu delete-menu.php sql injection — Online Food Menu CWE-89 4.7 Medium 2024-09-07
CVE-2024-8558 SourceCodester Food Ordering Management System Price place-order.php improper validation of specified quantity in input — Food Ordering Management System CWE-1284 4.3 Medium 2024-09-07
CVE-2024-8557 SourceCodester Food Ordering Management System cancel-order.php sql injection — Food Ordering Management System CWE-89 6.3 Medium 2024-09-07
CVE-2024-8555 SourceCodester Clinics Patient Management System congratulations.php redirect — Clinics Patient Management System CWE-601 4.3 Medium 2024-09-07
CVE-2024-8554 SourceCodester Clinics Patient Management System users.php cross site scripting — Clinics Patient Management System CWE-79 3.5 Low 2024-09-07
CVE-2024-8416 SourceCodester Food Ordering Management System ticket-status.php sql injection — Food Ordering Management System CWE-89 6.3 Medium 2024-09-04
CVE-2024-8415 SourceCodester Food Ordering Management System add-ticket.php sql injection — Food Ordering Management System CWE-89 6.3 Medium 2024-09-04
CVE-2024-8414 SourceCodester Insurance Management System cross-site request forgery — Insurance Management System CWE-352 4.3 Medium 2024-09-04
CVE-2024-8380 SourceCodester Contact Manager with Export to VCF Delete Contact delete-account.php sql injection — Contact Manager with Export to VCF CWE-89 6.3 Medium 2024-09-03
CVE-2024-8348 SourceCodester Computer Laboratory Management System Master.php delete_category sql injection — Computer Laboratory Management System CWE-89 6.3 Medium 2024-08-30
CVE-2024-8347 SourceCodester Computer Laboratory Management System Master.php delete_record sql injection — Computer Laboratory Management System CWE-89 6.3 Medium 2024-08-30
CVE-2024-8346 SourceCodester Computer Laboratory Management System SystemSettings.php update_settings_info sql injection — Computer Laboratory Management System CWE-89 6.3 Medium 2024-08-30
CVE-2024-8345 SourceCodester Music Gallery Site Users.php sql injection — Music Gallery Site CWE-89 6.3 Medium 2024-08-30
CVE-2024-8343 SourceCodester Sentiment Based Movie Rating System User Registration Users.php sql injection — Sentiment Based Movie Rating System CWE-89 7.3 High 2024-08-30
CVE-2024-8342 SourceCodester Petshop Management System add_client.php unrestricted upload — Petshop Management System CWE-434 6.3 Medium 2024-08-30
CVE-2024-8341 SourceCodester Petshop Management System add_user.php unrestricted upload — Petshop Management System CWE-434 6.3 Medium 2024-08-30
CVE-2024-8340 SourceCodester Electric Billing Management System Actions.php sql injection — Electric Billing Management System CWE-89 7.3 High 2024-08-30
CVE-2024-8339 SourceCodester Electric Billing Management System Connection Code ?page=tracks sql injection — Electric Billing Management System CWE-89 6.3 Medium 2024-08-30
CVE-2024-8337 SourceCodester Contact Manager with Export to VCF index.html cross site scripting — Contact Manager with Export to VCF CWE-79 3.5 Low 2024-08-30
CVE-2024-8336 SourceCodester Music Gallery Site Master.php sql injection — Music Gallery Site CWE-89 6.3 Medium 2024-08-30
CVE-2024-8223 SourceCodester Music Gallery Site Master.php sql injection — Music Gallery Site CWE-89 6.3 Medium 2024-08-27

This page lists every published CVE security advisory associated with SourceCodester. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.