Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SourceCodester — Vulnerabilities & Security Advisories 1985

Browse all 1985 CVE security advisories affecting SourceCodester. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SourceCodester operates as a repository for free and premium source code, scripts, and web applications, primarily serving developers seeking ready-made solutions for rapid deployment. This business model inherently exposes users to significant security risks, as the platform hosts thousands of projects with varying levels of code review. Historically, vulnerabilities found in these downloads frequently include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from outdated frameworks or unpatched dependencies. Privilege escalation flaws are also common, allowing attackers to bypass authentication mechanisms. While SourceCodester does not typically manage post-download security patches, the sheer volume of recorded CVEs highlights systemic issues in code quality assurance. Users relying on these resources must perform rigorous independent security audits, as the platform’s primary focus remains distribution rather than comprehensive vulnerability management or remediation support.

CVE ID Title CVSS Severity Published
CVE-2023-7059 SourceCodester School Visitor Log e-Book log-book.php cross site scripting — School Visitor Log e-Book CWE-79 3.5 Low 2023-12-22
CVE-2023-7058 SourceCodester Simple Student Attendance System path traversal — Simple Student Attendance System CWE-24 6.3 Medium 2023-12-22
CVE-2023-6945 SourceCodester Online Student Management System edit-student-detail.php cross site scripting — Online Student Management System CWE-79 2.4 Low 2023-12-19
CVE-2023-6898 SourceCodester Best Courier Management System manage_user.php sql injection — Best Courier Management System CWE-89 5.5 Medium 2023-12-17
CVE-2023-6896 SourceCodester Simple Image Stack Website cross site scripting — Simple Image Stack Website CWE-79 3.5 Low 2023-12-17
CVE-2023-6771 SourceCodester Simple Student Attendance System actions.class.php save_attendance sql injection — Simple Student Attendance System CWE-89 5.5 Medium 2023-12-13
CVE-2023-6767 SourceCodester Wedding Guest e-Book add-guest.php cross site scripting — Wedding Guest e-Book CWE-79 4.3 Medium 2023-12-13
CVE-2023-6765 SourceCodester Online Tours & Travels Management System email_setup.php prepare sql injection — Online Tours & Travels Management System CWE-89 5.5 Medium 2023-12-13
CVE-2023-6658 SourceCodester Simple Student Attendance System sql injection — Simple Student Attendance System CWE-89 5.5 Medium 2023-12-10
CVE-2023-6657 SourceCodester Simple Student Attendance System student_form.php sql injection — Simple Student Attendance System CWE-89 5.5 Medium 2023-12-10
CVE-2023-6650 SourceCodester Simple Invoice Generator System login.php cross site scripting — Simple Invoice Generator System CWE-79 4.3 Medium 2023-12-10
CVE-2023-6619 SourceCodester Simple Student Attendance System class_form.php sql injection — Simple Student Attendance System CWE-89 5.5 Medium 2023-12-08
CVE-2023-6618 SourceCodester Simple Student Attendance System index.php file inclusion — Simple Student Attendance System CWE-73 5.5 Medium 2023-12-08
CVE-2023-6617 SourceCodester Simple Student Attendance System attendance.php sql injection — Simple Student Attendance System CWE-89 5.5 Medium 2023-12-08
CVE-2023-6616 SourceCodester Simple Student Attendance System index.php cross site scripting — Simple Student Attendance System CWE-79 3.5 Low 2023-12-08
CVE-2023-6473 SourceCodester Online Quiz System take-quiz.php cross site scripting — Online Quiz System CWE-79 3.5 Low 2023-12-02
CVE-2023-6464 SourceCodester User Registration and Login System add-user.php sql injection — User Registration and Login System CWE-89 6.3 Medium 2023-12-02
CVE-2023-6463 SourceCodester User Registration and Login System add-user.php cross site scripting — User Registration and Login System CWE-79 3.5 Low 2023-12-01
CVE-2023-6462 SourceCodester User Registration and Login System delete-user.php cross site scripting — User Registration and Login System CWE-79 3.5 Low 2023-12-01
CVE-2023-6440 SourceCodester Book Borrower System add-book.php cross site scripting — Book Borrower System CWE-79 3.5 Low 2023-11-30
CVE-2023-6313 SourceCodester URL Shortener Long URL cross site scripting — URL Shortener CWE-79 3.5 Low 2023-11-27
CVE-2023-6312 SourceCodester Loan Management System Users Page deleteUser.php delete_user sql injection — Loan Management System CWE-89 4.7 Medium 2023-11-27
CVE-2023-6311 SourceCodester Loan Management System Loan Type Page delete_ltype.php delete_ltype sql injection — Loan Management System CWE-89 4.7 Medium 2023-11-27
CVE-2023-6310 SourceCodester Loan Management System deleteBorrower.php delete_borrower sql injection — Loan Management System CWE-89 4.7 Medium 2023-11-27
CVE-2023-6306 SourceCodester Free and Open Source Inventory Management System member_data.php sql injection — Free and Open Source Inventory Management System CWE-89 6.3 Medium 2023-11-27
CVE-2023-6305 SourceCodester Free and Open Source Inventory Management System suppliar_data.php sql injection — Free and Open Source Inventory Management System CWE-89 6.3 Medium 2023-11-27
CVE-2023-6301 SourceCodester Best Courier Management System GET Parameter parcel_list.php cross site scripting — Best Courier Management System CWE-79 3.5 Low 2023-11-26
CVE-2023-6300 SourceCodester Best Courier Management System cross site scripting — Best Courier Management System CWE-79 3.5 Low 2023-11-26
CVE-2023-5919 SourceCodester Company Website CMS Create Blog Page createblog unrestricted upload — Company Website CMS CWE-434 4.7 Medium 2023-11-02
CVE-2023-5918 SourceCodester Visitor Management System manage_user.php sql injection — Visitor Management System CWE-89 6.3 Medium 2023-11-02

This page lists every published CVE security advisory associated with SourceCodester. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.