Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SourceCodester — Vulnerabilities & Security Advisories 1985

Browse all 1985 CVE security advisories affecting SourceCodester. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SourceCodester operates as a repository for free and premium source code, scripts, and web applications, primarily serving developers seeking ready-made solutions for rapid deployment. This business model inherently exposes users to significant security risks, as the platform hosts thousands of projects with varying levels of code review. Historically, vulnerabilities found in these downloads frequently include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from outdated frameworks or unpatched dependencies. Privilege escalation flaws are also common, allowing attackers to bypass authentication mechanisms. While SourceCodester does not typically manage post-download security patches, the sheer volume of recorded CVEs highlights systemic issues in code quality assurance. Users relying on these resources must perform rigorous independent security audits, as the platform’s primary focus remains distribution rather than comprehensive vulnerability management or remediation support.

CVE ID Title CVSS Severity Published
CVE-2024-2556 SourceCodester Employee Task Management System attendance-info.php sql injection — Employee Task Management System CWE-89 6.3 Medium 2024-03-17
CVE-2024-2555 SourceCodester Employee Task Management System update-admin.php sql injection — Employee Task Management System CWE-89 6.3 Medium 2024-03-17
CVE-2024-2554 SourceCodester Employee Task Management System update-employee.php sql injection — Employee Task Management System CWE-89 6.3 Medium 2024-03-17
CVE-2024-2553 SourceCodester Product Review Rating System Rate Product cross site scripting — Product Review Rating System CWE-79 3.5 Low 2024-03-17
CVE-2024-2418 SourceCodester Best POS Management System view_order.php sql injection — Best POS Management System CWE-89 6.3 Medium 2024-03-13
CVE-2024-2394 SourceCodester Employee Management System add-admin.php unrestricted upload — Employee Management System CWE-434 4.7 Medium 2024-03-12
CVE-2024-2393 SourceCodester CRUD without Page Reload add_user.php sql injection — CRUD without Page Reload CWE-89 6.3 Medium 2024-03-12
CVE-2024-2332 SourceCodester Online Mobile Management Store HTTP GET Request manage_category.php sql injection — Online Mobile Management Store CWE-89 6.3 Medium 2024-03-09
CVE-2024-2331 SourceCodester Tourist Reservation System System.cpp ad_writedata buffer overflow — Tourist Reservation System CWE-120 6.3 Medium 2024-03-09
CVE-2024-2168 SourceCodester Online Tours & Travels Management System HTTP POST Request expense_category.php sql injection — Online Tours & Travels Management System CWE-89 4.7 Medium 2024-03-04
CVE-2024-2156 SourceCodester Best POS Management System admin_class.php sql injection — Best POS Management System CWE-89 6.3 Medium 2024-03-04
CVE-2024-2155 SourceCodester Best POS Management System index.php file inclusion — Best POS Management System CWE-73 4.3 Medium 2024-03-04
CVE-2024-2154 SourceCodester Online Mobile Management Store view_product.php sql injection — Online Mobile Management Store CWE-89 6.3 Medium 2024-03-04
CVE-2024-2153 SourceCodester Online Mobile Management Store view_order.php sql injection — Online Mobile Management Store CWE-89 6.3 Medium 2024-03-04
CVE-2024-2152 SourceCodester Online Mobile Management Store manage_product.php sql injection — Online Mobile Management Store CWE-89 4.7 Medium 2024-03-04
CVE-2024-2151 SourceCodester Online Mobile Management Store Product Price logic error — Online Mobile Management Store CWE-840 4.3 Medium 2024-03-03
CVE-2024-2150 SourceCodester Insurance Management System file inclusion — Insurance Management System CWE-73 5.3 Medium 2024-03-03
CVE-2024-2148 SourceCodester Online Mobile Management Store Users.php unrestricted upload — Online Mobile Management Store CWE-434 6.3 Medium 2024-03-03
CVE-2024-2147 SourceCodester Online Mobile Management Store login.php sql injection — Online Mobile Management Store CWE-89 7.3 High 2024-03-03
CVE-2024-2146 SourceCodester Online Mobile Management Store ?p=products cross site scripting — Online Mobile Management Store CWE-79 3.5 Low 2024-03-03
CVE-2024-2145 SourceCodester Online Mobile Management Store update-tracker.php cross site scripting — Online Mobile Management Store CWE-79 3.5 Low 2024-03-03
CVE-2024-2077 SourceCodester Simple Online Bidding System index.php sql injection — Simple Online Bidding System CWE-89 6.3 Medium 2024-03-01
CVE-2024-2075 SourceCodester Daily Habit Tracker update-tracker.php cross site scripting — Daily Habit Tracker CWE-79 3.5 Low 2024-03-01
CVE-2024-2073 SourceCodester Block Inserter for Dynamic Content view_post.php sql injection — Block Inserter for Dynamic Content CWE-89 6.3 Medium 2024-03-01
CVE-2024-2072 SourceCodester Flashcard Quiz App update-flashcard.php cross site scripting — Flashcard Quiz App CWE-79 3.5 Low 2024-03-01
CVE-2024-2071 SourceCodester FAQ Management System Update FAQ cross site scripting — FAQ Management System CWE-79 3.5 Low 2024-03-01
CVE-2024-2070 SourceCodester FAQ Management System add-faq.php cross site scripting — FAQ Management System CWE-79 3.5 Low 2024-03-01
CVE-2024-2069 SourceCodester FAQ Management System delete-faq.php sql injection — FAQ Management System CWE-89 6.3 Medium 2024-03-01
CVE-2024-2068 SourceCodester Computer Inventory System update-computer.php cross site scripting — Computer Inventory System CWE-79 3.5 Low 2024-03-01
CVE-2024-2067 SourceCodester Computer Inventory System delete-computer.php sql injection — Computer Inventory System CWE-89 6.3 Medium 2024-03-01

This page lists every published CVE security advisory associated with SourceCodester. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.