Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SourceCodester — Vulnerabilities & Security Advisories 1985

Browse all 1985 CVE security advisories affecting SourceCodester. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SourceCodester operates as a repository for free and premium source code, scripts, and web applications, primarily serving developers seeking ready-made solutions for rapid deployment. This business model inherently exposes users to significant security risks, as the platform hosts thousands of projects with varying levels of code review. Historically, vulnerabilities found in these downloads frequently include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from outdated frameworks or unpatched dependencies. Privilege escalation flaws are also common, allowing attackers to bypass authentication mechanisms. While SourceCodester does not typically manage post-download security patches, the sheer volume of recorded CVEs highlights systemic issues in code quality assurance. Users relying on these resources must perform rigorous independent security audits, as the platform’s primary focus remains distribution rather than comprehensive vulnerability management or remediation support.

CVE ID Title CVSS Severity Published
CVE-2023-5269 SourceCodester Best Courier Management System GET Parameter parcel_list.php sql injection — Best Courier Management System CWE-89 5.5 Medium 2023-09-29
CVE-2023-5260 SourceCodester Simple Membership System group_validator.php sql injection — Simple Membership System CWE-89 6.3 Medium 2023-09-29
CVE-2023-5034 SourceCodester My Food Recipe Image Upload index.php unrestricted upload — My Food Recipe CWE-434 6.3 Medium 2023-09-18
CVE-2023-5027 SourceCodester Simple Membership System club_validator.php sql injection — Simple Membership System CWE-89 6.3 Medium 2023-09-17
CVE-2023-5021 SourceCodester AC Repair and Services System cross site scripting — AC Repair and Services System CWE-79 3.5 Low 2023-09-17
CVE-2023-5018 SourceCodester Lost and Found Information System POST Parameter sql injection — Lost and Found Information System CWE-89 6.3 Medium 2023-09-17
CVE-2023-4872 SourceCodester Contact Manager App add.php sql injection — Contact Manager App CWE-89 6.3 Medium 2023-09-10
CVE-2023-4871 SourceCodester Contact Manager App delete.php sql injection — Contact Manager App CWE-89 6.3 Medium 2023-09-10
CVE-2023-4870 SourceCodester Contact Manager App Contact Information index.php cross site scripting — Contact Manager App CWE-79 3.5 Low 2023-09-10
CVE-2023-4869 SourceCodester Contact Manager App update.php cross-site request forgery — Contact Manager App CWE-352 4.3 Medium 2023-09-10
CVE-2023-4868 SourceCodester Contact Manager App add.php cross-site request forgery — Contact Manager App CWE-352 4.3 Medium 2023-09-10
CVE-2023-4866 SourceCodester Online Tours & Travels Management System booking.php exec sql injection — Online Tours & Travels Management System CWE-89 6.3 Medium 2023-09-09
CVE-2023-4865 SourceCodester Take-Note App cross-site request forgery — Take-Note App CWE-352 4.3 Medium 2023-09-09
CVE-2023-4864 SourceCodester Take-Note App index.php cross site scripting — Take-Note App CWE-79 3.5 Low 2023-09-09
CVE-2023-4848 SourceCodester Simple Book Catalog App delete_book.php sql injection — Simple Book Catalog App CWE-89 6.3 Medium 2023-09-09
CVE-2023-4847 SourceCodester Simple Book Catalog App Update Book Form cross site scripting — Simple Book Catalog App CWE-79 3.5 Low 2023-09-09
CVE-2023-4846 SourceCodester Simple Membership System delete_member.php sql injection — Simple Membership System CWE-89 6.3 Medium 2023-09-09
CVE-2023-4845 SourceCodester Simple Membership System account_edit_query.php sql injection — Simple Membership System CWE-89 6.3 Medium 2023-09-09
CVE-2023-4844 SourceCodester Simple Membership System club_edit_query.php sql injection — Simple Membership System CWE-89 6.3 Medium 2023-09-08
CVE-2023-4749 SourceCodester Inventory Management System index.php file inclusion — Inventory Management System CWE-73 6.3 Medium 2023-09-04
CVE-2023-4558 SourceCodester Inventory Management System staff_data.php sql injection — Inventory Management System CWE-89 6.3 Medium 2023-08-27
CVE-2023-4557 SourceCodester Inventory Management System search_purchase_paymen_report.php sql injection — Inventory Management System CWE-89 6.3 Medium 2023-08-27
CVE-2023-4556 SourceCodester Online Graduate Tracer System sexit.php mysqli_query sql injection — Online Graduate Tracer System CWE-89 6.3 Medium 2023-08-27
CVE-2023-4555 SourceCodester Inventory Management System suppliar_data.php cross site scripting — Inventory Management System CWE-79 3.5 Low 2023-08-27
CVE-2023-4449 SourceCodester Free and Open Source Inventory Management System sql injection — Free and Open Source Inventory Management System CWE-89 6.3 Medium 2023-08-21
CVE-2023-4444 SourceCodester Free Hospital Management System for Small Practices edit-user.php sql injection — Free Hospital Management System for Small Practices CWE-89 6.3 Medium 2023-08-21
CVE-2023-4443 SourceCodester Free Hospital Management System for Small Practices edit-doc.php sql injection — Free Hospital Management System for Small Practices CWE-89 6.3 Medium 2023-08-21
CVE-2023-4442 SourceCodester Free Hospital Management System for Small Practices booking-complete.php sql injection — Free Hospital Management System for Small Practices CWE-89 6.3 Medium 2023-08-21
CVE-2023-4441 SourceCodester Free Hospital Management System for Small Practices appointment.php sql injection — Free Hospital Management System for Small Practices CWE-89 6.3 Medium 2023-08-20
CVE-2023-4440 SourceCodester Free Hospital Management System for Small Practices appointment.php sql injection — Free Hospital Management System for Small Practices CWE-89 6.3 Medium 2023-08-20

This page lists every published CVE security advisory associated with SourceCodester. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.