Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SourceCodester — Vulnerabilities & Security Advisories 1985

Browse all 1985 CVE security advisories affecting SourceCodester. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SourceCodester operates as a repository for free and premium source code, scripts, and web applications, primarily serving developers seeking ready-made solutions for rapid deployment. This business model inherently exposes users to significant security risks, as the platform hosts thousands of projects with varying levels of code review. Historically, vulnerabilities found in these downloads frequently include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from outdated frameworks or unpatched dependencies. Privilege escalation flaws are also common, allowing attackers to bypass authentication mechanisms. While SourceCodester does not typically manage post-download security patches, the sheer volume of recorded CVEs highlights systemic issues in code quality assurance. Users relying on these resources must perform rigorous independent security audits, as the platform’s primary focus remains distribution rather than comprehensive vulnerability management or remediation support.

CVE ID Title CVSS Severity Published
CVE-2024-7852 SourceCodester Yoga Class Registration System view_inquiry.php cross site scripting — Yoga Class Registration System CWE-79 3.5 Low 2024-08-16
CVE-2024-7851 SourceCodester Yoga Class Registration System Add User Users.php improper authorization — Yoga Class Registration System CWE-285 6.3 Medium 2024-08-16
CVE-2024-7845 SourceCodester Online Graduate Tracer System fetch_it.php sql injection — Online Graduate Tracer System CWE-89 6.3 Medium 2024-08-15
CVE-2024-7844 SourceCodester Online Graduate Tracer System add_acc.php cross site scripting — Online Graduate Tracer System CWE-79 3.5 Low 2024-08-15
CVE-2024-7843 SourceCodester Online Graduate Tracer System exportcs.php information disclosure — Online Graduate Tracer System CWE-200 5.3 Medium 2024-08-15
CVE-2024-7842 SourceCodester Online Graduate Tracer System export_it.php information disclosure — Online Graduate Tracer System CWE-200 5.3 Medium 2024-08-15
CVE-2024-7841 SourceCodester Clinics Patient Management System check_user_name.php sql injection — Clinics Patient Management System CWE-89 6.3 Medium 2024-08-15
CVE-2024-7813 SourceCodester Prison Management System Profile Image insufficiently protected credentials — Prison Management System CWE-522 5.3 Medium 2024-08-15
CVE-2024-7812 SourceCodester Best House Rental Management System POST Parameter ajax.php cross site scripting — Best House Rental Management System CWE-79 3.5 Low 2024-08-15
CVE-2024-7811 SourceCodester Daily Expenses Monitoring App delete-expense.php sql injection — Daily Expenses Monitoring App CWE-89 6.3 Medium 2024-08-15
CVE-2024-7810 SourceCodester Online Graduate Tracer System view_itprofile.php sql injection — Online Graduate Tracer System CWE-89 6.3 Medium 2024-08-15
CVE-2024-7809 SourceCodester Online Graduate Tracer System nbproject exposure of information through directory listing — Online Graduate Tracer System CWE-548 5.3 Medium 2024-08-15
CVE-2024-7800 SourceCodester Simple Online Bidding System ajax.php sql injection — Simple Online Bidding System CWE-89 6.3 Medium 2024-08-14
CVE-2024-7799 SourceCodester Simple Online Bidding System users.php improper authorization — Simple Online Bidding System CWE-285 5.3 Medium 2024-08-14
CVE-2024-7798 SourceCodester Simple Online Bidding System ajax.php sql injection — Simple Online Bidding System CWE-89 7.3 High 2024-08-14
CVE-2024-7797 SourceCodester Simple Online Bidding System ajax.php sql injection — Simple Online Bidding System CWE-89 7.3 High 2024-08-14
CVE-2024-7793 SourceCodester Task Progress Tracker add-task.php cross site scripting — Task Progress Tracker CWE-79 3.5 Low 2024-08-14
CVE-2024-7792 SourceCodester Task Progress Tracker delete-task.php sql injection — Task Progress Tracker CWE-89 6.3 Medium 2024-08-14
CVE-2024-7754 SourceCodester Clinics Patient Management System check_medicine_name.php sql injection — Clinics Patient Management System CWE-89 6.3 Medium 2024-08-14
CVE-2024-7753 SourceCodester Clinics Patient Management System user_images direct request — Clinics Patient Management System CWE-425 5.3 Medium 2024-08-14
CVE-2024-7752 SourceCodester Clinics Patient Management System update_medicine.php cross site scripting — Clinics Patient Management System CWE-79 3.5 Low 2024-08-13
CVE-2024-7751 SourceCodester Clinics Patient Management System update_medicine.php sql injection — Clinics Patient Management System CWE-89 6.3 Medium 2024-08-13
CVE-2024-7750 SourceCodester Clinics Patient Management System medicines.php sql injection — Clinics Patient Management System CWE-89 6.3 Medium 2024-08-13
CVE-2024-7749 SourceCodester Accounts Manager App add-account.php cross site scripting — Accounts Manager App CWE-79 3.5 Low 2024-08-13
CVE-2024-7748 SourceCodester Accounts Manager App delete-account.php sql injection — Accounts Manager App CWE-89 6.3 Medium 2024-08-13
CVE-2024-7686 SourceCodester Kortex Lite Advocate Office Management System register_case.php cross site scripting — Kortex Lite Advocate Office Management System CWE-79 3.5 Low 2024-08-12
CVE-2024-7685 SourceCodester Kortex Lite Advocate Office Management System adds.php cross site scripting — Kortex Lite Advocate Office Management System CWE-79 3.5 Low 2024-08-12
CVE-2024-7684 SourceCodester Kortex Lite Advocate Office Management System add_act.php cross site scripting — Kortex Lite Advocate Office Management System CWE-79 3.5 Low 2024-08-12
CVE-2024-7683 SourceCodester Kortex Lite Advocate Office Management System addcase_stage.php cross site scripting — Kortex Lite Advocate Office Management System CWE-79 3.5 Low 2024-08-12
CVE-2024-7678 SourceCodester Car Driving School Management System Master.php cross site scripting — Car Driving School Management System CWE-79 3.5 Low 2024-08-11

This page lists every published CVE security advisory associated with SourceCodester. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.