Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SourceCodester — Vulnerabilities & Security Advisories 1985

Browse all 1985 CVE security advisories affecting SourceCodester. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SourceCodester operates as a repository for free and premium source code, scripts, and web applications, primarily serving developers seeking ready-made solutions for rapid deployment. This business model inherently exposes users to significant security risks, as the platform hosts thousands of projects with varying levels of code review. Historically, vulnerabilities found in these downloads frequently include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from outdated frameworks or unpatched dependencies. Privilege escalation flaws are also common, allowing attackers to bypass authentication mechanisms. While SourceCodester does not typically manage post-download security patches, the sheer volume of recorded CVEs highlights systemic issues in code quality assurance. Users relying on these resources must perform rigorous independent security audits, as the platform’s primary focus remains distribution rather than comprehensive vulnerability management or remediation support.

CVE ID Title CVSS Severity Published
CVE-2024-2066 SourceCodester Computer Inventory System add-computer.php cross site scripting — Computer Inventory System CWE-79 2.4 Low 2024-03-01
CVE-2024-2065 SourceCodester Barangay Population Monitoring System update-resident.php cross site scripting — Barangay Population Monitoring System CWE-79 3.5 Low 2024-03-01
CVE-2024-2063 SourceCodester Petrol Pump Management Software profile_crud.php cross site scripting — Petrol Pump Management Software CWE-79 2.4 Low 2024-03-01
CVE-2024-2062 SourceCodester Petrol Pump Management Software edit_categories.php sql injection — Petrol Pump Management Software CWE-89 4.7 Medium 2024-03-01
CVE-2024-2061 SourceCodester Petrol Pump Management Software edit_supplier.php sql injection — Petrol Pump Management Software CWE-89 4.7 Medium 2024-03-01
CVE-2024-2060 SourceCodester Petrol Pump Management Software login_crud.php sql injection — Petrol Pump Management Software CWE-89 4.7 Medium 2024-03-01
CVE-2024-2059 SourceCodester Petrol Pump Management Software service_crud.php unrestricted upload — Petrol Pump Management Software CWE-434 4.7 Medium 2024-03-01
CVE-2024-2058 SourceCodester Petrol Pump Management Software product.php unrestricted upload — Petrol Pump Management Software CWE-434 4.7 Medium 2024-03-01
CVE-2024-1972 SourceCodester Online Job Portal EditProfile.php cross site scripting — Online Job Portal CWE-79 3.5 Low 2024-02-28
CVE-2024-1970 SourceCodester Online Learning System V2 index.php cross site scripting — Online Learning System V2 CWE-79 4.3 Medium 2024-02-28
CVE-2024-1928 SourceCodester Web-Based Student Clearance System Edit User Profile Page edit-admin.php sql injection — Web-Based Student Clearance System CWE-89 4.7 Medium 2024-02-27
CVE-2024-1927 SourceCodester Web-Based Student Clearance System login.php sql injection — Web-Based Student Clearance System CWE-89 6.3 Medium 2024-02-27
CVE-2024-1926 SourceCodester Free and Open Source Inventory Management System search_sales_report.php sql injection — Free and Open Source Inventory Management System CWE-89 6.3 Medium 2024-02-27
CVE-2024-1923 SourceCodester Simple Student Attendance System List of Classes Page ajax-api.php delete_student sql injection — Simple Student Attendance System CWE-89 6.3 Medium 2024-02-27
CVE-2024-1922 SourceCodester Online Job Portal Manage Job Page ManageJob.php cross site scripting — Online Job Portal CWE-79 3.5 Low 2024-02-27
CVE-2024-1919 SourceCodester Online Job Portal Manage Walkin Page ManageWalkin.php cross site scripting — Online Job Portal CWE-79 3.5 Low 2024-02-27
CVE-2024-1878 SourceCodester Employee Management System myprofile.php sql injection — Employee Management System CWE-89 6.3 Medium 2024-02-26
CVE-2024-1877 SourceCodester Employee Management System cancel.php sql injection — Employee Management System CWE-89 6.3 Medium 2024-02-26
CVE-2024-1876 SourceCodester Employee Management System psubmit.php sql injection — Employee Management System CWE-89 7.3 High 2024-02-26
CVE-2024-1875 SourceCodester Complaint Management System Lodge Complaint Section register-complaint.php unrestricted upload — Complaint Management System CWE-434 6.3 Medium 2024-02-25
CVE-2024-1871 SourceCodester Employee Management System Project Assignment Report assignp.php cross site scripting — Employee Management System CWE-79 3.5 Low 2024-02-24
CVE-2024-1834 SourceCodester Simple Student Attendance System ?page=attendance&class_id=1 cross site scripting — Simple Student Attendance System CWE-79 3.5 Low 2024-02-23
CVE-2024-1833 SourceCodester Employee Management System login.php sql injection — Employee Management System CWE-89 7.3 High 2024-02-23
CVE-2024-1832 SourceCodester Complete File Management System Admin Login Form sql injection — Complete File Management System CWE-89 7.3 High 2024-02-23
CVE-2024-1831 SourceCodester Complete File Management System Login Form index.php sql injection — Complete File Management System CWE-89 7.3 High 2024-02-23
CVE-2024-1269 SourceCodester Product Management System supplier.php cross site scripting — Product Management System CWE-79 2.4 Low 2024-02-07
CVE-2024-1215 SourceCodester CRUD without Page Reload fetch_data.php cross site scripting — CRUD without Page Reload CWE-79 3.5 Low 2024-02-03
CVE-2024-1197 SourceCodester Testimonial Page Manager HTTP GET Request delete-testimonial.php sql injection — Testimonial Page Manager CWE-89 7.3 High 2024-02-02
CVE-2024-1196 SourceCodester Testimonial Page Manager HTTP POST Request add-testimonial.php cross site scripting — Testimonial Page Manager CWE-79 4.3 Medium 2024-02-02
CVE-2024-1111 SourceCodester QR Code Login System add-user.php cross site scripting — QR Code Login System CWE-79 4.3 Medium 2024-01-31

This page lists every published CVE security advisory associated with SourceCodester. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.