Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SourceCodester — Vulnerabilities & Security Advisories 1985

Browse all 1985 CVE security advisories affecting SourceCodester. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SourceCodester operates as a repository for free and premium source code, scripts, and web applications, primarily serving developers seeking ready-made solutions for rapid deployment. This business model inherently exposes users to significant security risks, as the platform hosts thousands of projects with varying levels of code review. Historically, vulnerabilities found in these downloads frequently include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from outdated frameworks or unpatched dependencies. Privilege escalation flaws are also common, allowing attackers to bypass authentication mechanisms. While SourceCodester does not typically manage post-download security patches, the sheer volume of recorded CVEs highlights systemic issues in code quality assurance. Users relying on these resources must perform rigorous independent security audits, as the platform’s primary focus remains distribution rather than comprehensive vulnerability management or remediation support.

CVE ID Title CVSS Severity Published
CVE-2022-2767 SourceCodester Online Admission System index.php cross site scripting — Online Admission System CWE-79 3.5 Low 2022-08-11
CVE-2022-2766 SourceCodester Loan Management System index.php sql injection — Loan Management System CWE-89 7.3 High 2022-08-11
CVE-2022-2765 SourceCodester Company Website CMS settings improper authentication — Company Website CMS CWE-287 6.3 Medium 2022-08-11
CVE-2022-2751 SourceCodester Company Website CMS add-portfolio.php unrestricted upload — Company Website CMS CWE-434 6.3 Medium 2022-08-11
CVE-2022-2750 SourceCodester Company Website CMS Add Service add-service.php unrestricted upload — Company Website CMS CWE-434 6.3 Medium 2022-08-11
CVE-2022-2749 SourceCodester Gym Management System unrestricted upload — Gym Management System CWE-434 4.7 Medium 2022-08-11
CVE-2022-2748 SourceCodester Simple Online Book Store System edit.php cross site scripting — Simple Online Book Store System CWE-79 3.5 Low 2022-08-11
CVE-2022-2747 SourceCodester Simple Online Book Store book.php sql injection — Simple Online Book Store CWE-89 6.3 Medium 2022-08-11
CVE-2022-2746 SourceCodester Simple Online Book Store System Admin_ add.php unrestricted upload — Simple Online Book Store System CWE-434 6.3 Medium 2022-08-11
CVE-2022-2745 SourceCodester Gym Management System Add New Trainer add_trainers.php sql injection — Gym Management System CWE-89 6.3 Medium 2022-08-11
CVE-2022-2744 SourceCodester Gym Management System Background Management add_exercises.php unrestricted upload — Gym Management System CWE-434 6.3 Medium 2022-08-11
CVE-2022-2740 SourceCodester Company Website CMS Add Blog add-blog.php unrestricted upload — Company Website CMS CWE-434 6.3 Medium 2022-08-11
CVE-2022-2736 SourceCodester Company Website CMS Background Upload Logo Icon updatelogo.php unrestricted upload — Company Website CMS CWE-434 6.3 Medium 2022-08-11
CVE-2022-2728 SourceCodester Gym Management System index.php sql injection — Gym Management System CWE-89 6.3 Medium 2022-08-09
CVE-2022-2727 SourceCodester Gym Management System login.php sql injection — Gym Management System CWE-89 6.3 Medium 2022-08-09
CVE-2022-2725 SourceCodester Company Website CMS add-blog.php cross site scripting — Company Website CMS CWE-79 3.5 Low 2022-08-09
CVE-2022-2724 SourceCodester Employee Management System aprocess.php sql injection — Employee Management System CWE-89 6.3 Medium 2022-08-09
CVE-2022-2723 SourceCodester Employee Management System eprocess.php sql injection — Employee Management System CWE-89 6.3 Medium 2022-08-09
CVE-2022-2722 SourceCodester Simple Student Information System manage_course.php sql injection — Simple Student Information System CWE-89 6.3 Medium 2022-08-09
CVE-2022-2715 SourceCodester Employee Management System eloginwel.php sql injection — Employee Management System CWE-89 6.3 Medium 2022-08-09
CVE-2022-2708 SourceCodester Gym Management System login.php sql injection — Gym Management System CWE-89 5.5 Medium 2022-08-08
CVE-2022-2707 SourceCodester Online Class and Exam Scheduling System faculty_sched.php sql injection — Online Class and Exam Scheduling System CWE-89 6.3 Medium 2022-08-08
CVE-2022-2706 SourceCodester Online Class and Exam Scheduling System class_sched.php sql injection — Online Class and Exam Scheduling System CWE-89 6.3 Medium 2022-08-08
CVE-2022-2705 SourceCodester Simple Student Information System manage_department.php sql injection — Simple Student Information System CWE-89 6.3 Medium 2022-08-08
CVE-2022-2704 SourceCodester Simple E-Learning System downloadFiles.php information disclosure — Simple E-Learning System CWE-200 4.3 Medium 2022-08-08
CVE-2022-2703 SourceCodester Gym Management System Exercises Module sql injection — Gym Management System CWE-89 6.3 Medium 2022-08-08
CVE-2022-2702 SourceCodester Company Website CMS Cookie site-settings.php access control — Company Website CMS CWE-284 7.3 High 2022-08-08
CVE-2022-2701 SourceCodester Simple E-Learning System claire_blake cross site scripting — Simple E-Learning System CWE-79 3.5 Low 2022-08-08
CVE-2022-2700 SourceCodester Gym Management System GET Parameter sql injection — Gym Management System CWE-89 4.7 Medium 2022-08-08
CVE-2022-2699 SourceCodester Simple E-Learning System claire_blake sql injection — Simple E-Learning System CWE-89 6.3 Medium 2022-08-08

This page lists every published CVE security advisory associated with SourceCodester. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.