Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SourceCodester — Vulnerabilities & Security Advisories 1985

Browse all 1985 CVE security advisories affecting SourceCodester. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SourceCodester operates as a repository for free and premium source code, scripts, and web applications, primarily serving developers seeking ready-made solutions for rapid deployment. This business model inherently exposes users to significant security risks, as the platform hosts thousands of projects with varying levels of code review. Historically, vulnerabilities found in these downloads frequently include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from outdated frameworks or unpatched dependencies. Privilege escalation flaws are also common, allowing attackers to bypass authentication mechanisms. While SourceCodester does not typically manage post-download security patches, the sheer volume of recorded CVEs highlights systemic issues in code quality assurance. Users relying on these resources must perform rigorous independent security audits, as the platform’s primary focus remains distribution rather than comprehensive vulnerability management or remediation support.

CVE ID Title CVSS Severity Published
CVE-2022-3332 SourceCodester Food Ordering Management System POST Parameter router.php sql injection — Food Ordering Management System CWE-707 6.3 Medium 2022-09-28
CVE-2022-3122 SourceCodester Clinics Patient Management System medicine_details.php sql injection — Clinics Patient Management System CWE-89 6.3 Medium 2022-09-05
CVE-2022-3121 SourceCodester Online Employee Leave Management System addemployee.php cross-site request forgery — Online Employee Leave Management System CWE-352 4.3 Medium 2022-09-05
CVE-2022-3120 SourceCodester Clinics Patient Management System Login index.php sql injection — Clinics Patient Management System CWE-89 7.3 High 2022-09-05
CVE-2022-3014 SourceCodester Simple Task Managing System cross site scripting — Simple Task Managing System CWE-79 3.5 Low 2022-08-27
CVE-2022-3013 SourceCodester Simple Task Managing System loginVaLidation.php sql injection — Simple Task Managing System CWE-89 6.3 Medium 2022-08-27
CVE-2022-2957 SourceCodester Simple and Nice Shopping Cart Script profile.php sql injection — Simple and Nice Shopping Cart Script CWE-89 6.3 Medium 2022-08-25
CVE-2022-2842 SourceCodester Gym Management System login.php sql injection — Gym Management System CWE-89 7.3 High 2022-08-22
CVE-2022-2909 SourceCodester Simple and Nice Shopping Cart Script profile.php unrestricted upload — Simple and Nice Shopping Cart Script CWE-434 6.3 Medium 2022-08-20
CVE-2022-2876 SourceCodester Student Management System index.php sql injection — Student Management System CWE-89 6.3 Medium 2022-08-18
CVE-2022-2847 SourceCodester Guest Management System front.php sql injection — Guest Management System CWE-89 6.3 Medium 2022-08-16
CVE-2022-2814 SourceCodester Simple and Nice Shopping Cart Script login.php cross site scripting — Simple and Nice Shopping Cart Script CWE-79 3.5 Low 2022-08-15
CVE-2022-2813 SourceCodester Guest Management System cleartext storage — Guest Management System CWE-312 4.3 Medium 2022-08-14
CVE-2022-2812 SourceCodester Guest Management System index.php sql injection — Guest Management System CWE-89 7.3 High 2022-08-14
CVE-2022-2811 SourceCodester Guest Management System myform.php cross site scripting — Guest Management System CWE-79 3.5 Low 2022-08-14
CVE-2022-2804 SourceCodester Zoo Management System apply_vacancy.php unrestricted upload — Zoo Management System CWE-434 6.3 Medium 2022-08-12
CVE-2022-2803 SourceCodester Zoo Management System animals.php sql injection — Zoo Management System CWE-89 6.3 Medium 2022-08-12
CVE-2022-2802 SourceCodester Gas Agency Management System login.php sql injection — Gas Agency Management System CWE-89 7.3 High 2022-08-12
CVE-2022-2801 SourceCodester Automated Beer Parlour Billing System Login sql injection — Automated Beer Parlour Billing System CWE-89 6.3 Medium 2022-08-12
CVE-2022-2800 SourceCodester Gym Management System clickjacking — Gym Management System CWE-451 4.3 Medium 2022-08-12
CVE-2022-2797 SourceCodester Student Information System view_student.php sql injection — Student Information System CWE-89 6.3 Medium 2022-08-12
CVE-2022-2779 SourceCodester Gas Agency Management System oneWord.php unrestricted upload — Gas Agency Management System CWE-434 6.3 Medium 2022-08-12
CVE-2022-2776 SourceCodester Gym Management System delete_user.php denial of service — Gym Management System CWE-404 5.4 Medium 2022-08-11
CVE-2022-2774 SourceCodester Library Management System student.php sql injection — Library Management System CWE-89 6.3 Medium 2022-08-11
CVE-2022-2773 SourceCodester Apartment Visitor Management System profile.php cross site scripting — Apartment Visitor Management System CWE-79 3.5 Low 2022-08-11
CVE-2022-2772 SourceCodester Apartment Visitor Management System action-visitor.php sql injection — Apartment Visitor Management System CWE-89 6.3 Medium 2022-08-11
CVE-2022-2771 SourceCodester Simple Online Book Store System bookPerPub.php sql injection — Simple Online Book Store System CWE-89 6.3 Medium 2022-08-11
CVE-2022-2770 SourceCodester Simple Online Book Store System book.php sql injection — Simple Online Book Store System CWE-89 6.3 Medium 2022-08-11
CVE-2022-2769 SourceCodester Company Website CMS contact cross site scripting — Company Website CMS CWE-79 3.5 Low 2022-08-11
CVE-2022-2768 SourceCodester Library Management System cross site scripting — Library Management System CWE-79 3.5 Low 2022-08-11

This page lists every published CVE security advisory associated with SourceCodester. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.