Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SourceCodester — Vulnerabilities & Security Advisories 1985

Browse all 1985 CVE security advisories affecting SourceCodester. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SourceCodester operates as a repository for free and premium source code, scripts, and web applications, primarily serving developers seeking ready-made solutions for rapid deployment. This business model inherently exposes users to significant security risks, as the platform hosts thousands of projects with varying levels of code review. Historically, vulnerabilities found in these downloads frequently include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from outdated frameworks or unpatched dependencies. Privilege escalation flaws are also common, allowing attackers to bypass authentication mechanisms. While SourceCodester does not typically manage post-download security patches, the sheer volume of recorded CVEs highlights systemic issues in code quality assurance. Users relying on these resources must perform rigorous independent security audits, as the platform’s primary focus remains distribution rather than comprehensive vulnerability management or remediation support.

CVE ID Title CVSS Severity Published
CVE-2022-3581 SourceCodester Cashier Queuing System Cashiers Tab cross site scripting — Cashier Queuing System CWE-707 2.4 Low 2022-10-18
CVE-2022-3582 SourceCodester Simple Cold Storage Management System cross-site request forgery — Simple Cold Storage Management System CWE-863 4.3 Medium 2022-10-18
CVE-2022-3583 SourceCodester Canteen Management System login.php sql injection — Canteen Management System CWE-707 7.3 High 2022-10-18
CVE-2022-3584 SourceCodester Canteen Management System edituser.php sql injection — Canteen Management System CWE-707 6.3 Medium 2022-10-18
CVE-2022-3585 SourceCodester Simple Cold Storage Management System Contact Us cross-site request forgery — Simple Cold Storage Management System CWE-863 4.3 Medium 2022-10-18
CVE-2022-3587 SourceCodester Simple Cold Storage Management System My Account cross site scripting — Simple Cold Storage Management System CWE-707 3.5 Low 2022-10-18
CVE-2022-3546 SourceCodester Simple Cold Storage Management System Create User cross site scripting — Simple Cold Storage Management System CWE-707 2.4 Low 2022-10-17
CVE-2022-3547 SourceCodester Simple Cold Storage Management System Setting cross site scripting — Simple Cold Storage Management System CWE-707 2.4 Low 2022-10-17
CVE-2022-3548 SourceCodester Simple Cold Storage Management System Add New Storage cross site scripting — Simple Cold Storage Management System CWE-707 2.4 Low 2022-10-17
CVE-2022-3549 SourceCodester Simple Cold Storage Management System Avatar unrestricted upload — Simple Cold Storage Management System CWE-266 4.7 Medium 2022-10-17
CVE-2022-3518 SourceCodester Sanitization Management System User Creation cross site scripting — Sanitization Management System CWE-707 2.4 Low 2022-10-15
CVE-2022-3519 SourceCodester Sanitization Management System Quote Requests Tab cross site scripting — Sanitization Management System CWE-707 2.4 Low 2022-10-15
CVE-2022-3495 SourceCodester Simple Online Public Access Catalog Admin Login sql injection — Simple Online Public Access Catalog CWE-707 7.3 High 2022-10-14
CVE-2022-3496 SourceCodester Human Resource Management System Admin Panel employeeadd.php access control — Human Resource Management System CWE-266 6.3 Medium 2022-10-14
CVE-2022-3497 SourceCodester Human Resource Management System Master List cross site scripting — Human Resource Management System CWE-707 3.5 Low 2022-10-14
CVE-2022-3503 SourceCodester Purchase Order Management System Supplier cross site scripting — Purchase Order Management System CWE-707 3.5 Low 2022-10-14
CVE-2022-3504 SourceCodester Sanitization Management System sql injection — Sanitization Management System CWE-707 6.3 Medium 2022-10-14
CVE-2022-3505 SourceCodester Sanitization Management System cross site scripting — Sanitization Management System CWE-707 3.5 Low 2022-10-14
CVE-2022-3492 SourceCodester Human Resource Management System Profile Photo os command injection — Human Resource Management System CWE-707 6.3 Medium 2022-10-13
CVE-2022-3493 SourceCodester Human Resource Management System Add Employee cross site scripting — Human Resource Management System CWE-707 3.5 Low 2022-10-13
CVE-2022-3458 SourceCodester Human Resource Management System Image File employeeview.php unrestricted upload — Human Resource Management System CWE-266 6.3 Medium 2022-10-12
CVE-2022-3470 SourceCodester Human Resource Management System getstatecity.php sql injection — Human Resource Management System CWE-707 6.3 Medium 2022-10-12
CVE-2022-3471 SourceCodester Human Resource Management System city.php sql injection — Human Resource Management System CWE-707 6.3 Medium 2022-10-12
CVE-2022-3472 SourceCodester Human Resource Management System city.php sql injection — Human Resource Management System CWE-707 6.3 Medium 2022-10-12
CVE-2022-3473 SourceCodester Human Resource Management System getstatecity.php sql injection — Human Resource Management System CWE-707 6.3 Medium 2022-10-12
CVE-2022-3452 SourceCodester Book Store Management System category.php cross site scripting — Book Store Management System CWE-707 3.5 Low 2022-10-11
CVE-2022-3453 SourceCodester Book Store Management System transcation.php cross site scripting — Book Store Management System CWE-707 3.5 Low 2022-10-11
CVE-2022-3436 SourceCodester Web-Based Student Clearance System Photo edit-photo.php unrestricted upload — Web-Based Student Clearance System CWE-266 6.3 Medium 2022-10-09
CVE-2022-3434 SourceCodester Web-Based Student Clearance System add-student.php prepare cross site scripting — Web-Based Student Clearance System CWE-707 3.5 Low 2022-10-08
CVE-2022-3414 SourceCodester Web-Based Student Clearance System POST Parameter login.php sql injection — Web-Based Student Clearance System CWE-707 5.0 Medium 2022-10-07

This page lists every published CVE security advisory associated with SourceCodester. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.