Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SourceCodester — Vulnerabilities & Security Advisories 1985

Browse all 1985 CVE security advisories affecting SourceCodester. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SourceCodester operates as a repository for free and premium source code, scripts, and web applications, primarily serving developers seeking ready-made solutions for rapid deployment. This business model inherently exposes users to significant security risks, as the platform hosts thousands of projects with varying levels of code review. Historically, vulnerabilities found in these downloads frequently include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from outdated frameworks or unpatched dependencies. Privilege escalation flaws are also common, allowing attackers to bypass authentication mechanisms. While SourceCodester does not typically manage post-download security patches, the sheer volume of recorded CVEs highlights systemic issues in code quality assurance. Users relying on these resources must perform rigorous independent security audits, as the platform’s primary focus remains distribution rather than comprehensive vulnerability management or remediation support.

CVE ID Title CVSS Severity Published
CVE-2026-14776 SourceCodester Onlne Examination & Learning Management System Filename Extension upload_files.php pathinfo unrestricted upload — Onlne Examination & Learning Management System CWE-434 6.3 Medium 2026-07-05
CVE-2026-14775 SourceCodester Onlne Examination & Learning Management System process_lesson.php unrestricted upload — Onlne Examination & Learning Management System CWE-434 6.3 Medium 2026-07-05
CVE-2026-14772 SourceCodester Class and Exam Timetabling System edit_course1.php sql injection — Class and Exam Timetabling System CWE-89 7.3 High 2026-07-05
CVE-2026-14771 SourceCodester Class and Exam Timetabling System edit_exam1.php sql injection — Class and Exam Timetabling System CWE-89 7.3 High 2026-07-05
CVE-2026-14770 SourceCodester Class and Exam Timetabling System edit_room.php sql injection — Class and Exam Timetabling System CWE-89 7.3 High 2026-07-05
CVE-2026-14734 SourceCodester Class and Exam Timetabling System edit_product.php sql injection — Class and Exam Timetabling System CWE-89 7.3 High 2026-07-05
CVE-2026-14733 SourceCodester Class and Exam Timetabling System edit_coursea.php sql injection — Class and Exam Timetabling System CWE-89 7.3 High 2026-07-05
CVE-2026-14732 SourceCodester Class and Exam Timetabling System edit_exam.php sql injection — Class and Exam Timetabling System CWE-89 7.3 High 2026-07-05
CVE-2026-14725 SourceCodester Online Boat Reservation System session expiration — Online Boat Reservation System CWE-613 6.3 Medium 2026-07-05
CVE-2026-14719 SourceCodester Onlne Examination & Learning Management System Registration Endpoint register.php privileges management — Onlne Examination & Learning Management System CWE-269 7.3 High 2026-07-05
CVE-2026-14713 SourceCodester Pizzafy E-Commerce System ajax.php confirm_order sql injection — Pizzafy E-Commerce System CWE-89 7.3 High 2026-07-05
CVE-2026-14698 SourceCodester Syllabus-Aligned Learning Management and Examination System upload_files.php unrestricted upload — Syllabus-Aligned Learning Management and Examination System CWE-434 6.3 Medium 2026-07-05
CVE-2026-14695 SourceCodester Multi-Vendor Online Grocery Management System Registration Users.php save_client sql injection — Multi-Vendor Online Grocery Management System CWE-89 7.3 High 2026-07-05
CVE-2026-14694 SourceCodester Multi-Vendor Online Grocery Management System POST Parameter Master.php cancel_order sql injection — Multi-Vendor Online Grocery Management System CWE-89 6.3 Medium 2026-07-05
CVE-2026-14693 SourceCodester Multi-Vendor Online Grocery Management System Master.php cancel_order improper authorization — Multi-Vendor Online Grocery Management System CWE-285 5.4 Medium 2026-07-05
CVE-2026-14692 SourceCodester Multi-Vendor Online Grocery Management System POST Parameter Master.php save_shop_type sql injection — Multi-Vendor Online Grocery Management System CWE-89 6.3 Medium 2026-07-05
CVE-2026-14691 SourceCodester Multi-Vendor Online Grocery Management System Setting SystemSettings.php update_settings_info code injection — Multi-Vendor Online Grocery Management System CWE-94 6.3 Medium 2026-07-05
CVE-2026-14690 SourceCodester Multi-Vendor Online Grocery Management System Users.php save_users improper authorization — Multi-Vendor Online Grocery Management System CWE-285 7.3 High 2026-07-05
CVE-2026-14654 SourceCodester Simple and Nice Shopping Cart Script girlsproductdeletequery.php sql injection — Simple and Nice Shopping Cart Script CWE-89 7.3 High 2026-07-04
CVE-2026-14653 SourceCodester Simple and Nice Shopping Cart Script mensproductdeletequery.php sql injection — Simple and Nice Shopping Cart Script CWE-89 7.3 High 2026-07-04
CVE-2026-14652 SourceCodester Simple and Nice Shopping Cart Script Admin Login login.php sql injection — Simple and Nice Shopping Cart Script CWE-89 7.3 High 2026-07-04
CVE-2026-14642 SourceCodester Class and Exam Timetabling System edit_class2.php sql injection — Class and Exam Timetabling System CWE-89 7.3 High 2026-07-04
CVE-2026-14641 SourceCodester Class and Exam Timetabling System edit_course.php sql injection — Class and Exam Timetabling System CWE-89 7.3 High 2026-07-04
CVE-2026-14609 SourceCodester CET Automated Grading System with AI Predictive Analytics session fixiation — CET Automated Grading System with AI Predictive Analytics CWE-384 5.6 Medium 2026-07-03
CVE-2026-14608 SourceCodester CET Automated Grading System with AI Predictive Analytics POST index.php view_student authorization — CET Automated Grading System with AI Predictive Analytics CWE-639 4.3 Medium 2026-07-03
CVE-2026-13571 SourceCodester Simple Food Ordering System cart.php logic error — Simple Food Ordering System CWE-840 5.3 Medium 2026-06-29
CVE-2026-13570 SourceCodester Inventory Management System User Registration Endpoint users_handler.php cross site scripting — Inventory Management System CWE-79 3.5 Low 2026-06-29
CVE-2026-13568 SourceCodester Inventory Management System User Registration Endpoint users_handler.php access control — Inventory Management System CWE-284 7.3 High 2026-06-29
CVE-2026-13566 SourceCodester Class and Exam Timetabling System preview3.php sql injection — Class and Exam Timetabling System CWE-89 7.3 High 2026-06-29
CVE-2026-13565 SourceCodester Class and Exam Timetabling System edit_class1.php sql injection — Class and Exam Timetabling System CWE-89 7.3 High 2026-06-29

This page lists every published CVE security advisory associated with SourceCodester. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.