Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SourceCodester — Vulnerabilities & Security Advisories 1985

Browse all 1985 CVE security advisories affecting SourceCodester. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SourceCodester operates as a repository for free and premium source code, scripts, and web applications, primarily serving developers seeking ready-made solutions for rapid deployment. This business model inherently exposes users to significant security risks, as the platform hosts thousands of projects with varying levels of code review. Historically, vulnerabilities found in these downloads frequently include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from outdated frameworks or unpatched dependencies. Privilege escalation flaws are also common, allowing attackers to bypass authentication mechanisms. While SourceCodester does not typically manage post-download security patches, the sheer volume of recorded CVEs highlights systemic issues in code quality assurance. Users relying on these resources must perform rigorous independent security audits, as the platform’s primary focus remains distribution rather than comprehensive vulnerability management or remediation support.

CVE ID Title CVSS Severity Published
CVE-2026-9412 SourceCodester Indian Invoicing System Backend Endpoint access control — Indian Invoicing System CWE-284 6.3 Medium 2026-05-25
CVE-2026-9411 SourceCodester Indian Invoicing System Invoice Generation IGST_Invoice.php sql injection — Indian Invoicing System CWE-89 6.3 Medium 2026-05-25
CVE-2026-9377 SourceCodester SUP Online Shopping productedit.php cross site scripting — SUP Online Shopping CWE-79 2.4 Low 2026-05-24
CVE-2026-9356 SourceCodester Hospitals Patient Records Management System manage_history.php sql injection — Hospitals Patient Records Management System CWE-89 7.3 High 2026-05-24
CVE-2026-9355 SourceCodester Hospitals Patient Records Management System Master.php save_patient_history sql injection — Hospitals Patient Records Management System CWE-89 7.3 High 2026-05-24
CVE-2026-9342 SourceCodester Hospitals Patient Records Management System view_history.php sql injection — Hospitals Patient Records Management System CWE-89 6.3 Medium 2026-05-23
CVE-2026-8136 SourceCodester Pharmacy Sales and Inventory System index.php users cross site scripting — Pharmacy Sales and Inventory System CWE-79 2.4 Low 2026-05-08
CVE-2026-8131 SourceCodester SUP Online Shopping replymsg.php sql injection — SUP Online Shopping CWE-89 7.3 High 2026-05-08
CVE-2026-8130 SourceCodester SUP Online Shopping message.php sql injection — SUP Online Shopping CWE-89 7.3 High 2026-05-08
CVE-2026-8129 SourceCodester SUP Online Shopping wishlist.php sql injection — SUP Online Shopping CWE-89 7.3 High 2026-05-08
CVE-2026-8128 SourceCodester SUP Online Shopping viewmsg.php sql injection — SUP Online Shopping CWE-89 7.3 High 2026-05-08
CVE-2026-8126 SourceCodester Comment System post_comment.php sql injection — Comment System CWE-89 7.3 High 2026-05-08
CVE-2026-8117 SourceCodester Pizzafy Ecommerce System index.php cross site scripting — Pizzafy Ecommerce System CWE-79 4.3 Medium 2026-05-07
CVE-2026-8083 SourceCodester Pharmacy Sales and Inventory System ajax.php save_user sql injection — Pharmacy Sales and Inventory System CWE-89 7.3 High 2026-05-07
CVE-2026-7746 SourceCodester Web-based Pharmacy Product Management System edit-admin.php sql injection — Web-based Pharmacy Product Management System CWE-89 6.3 Medium 2026-05-04
CVE-2026-7550 SourceCodester Pharmacy Sales and Inventory System ajax.php save_customer sql injection — Pharmacy Sales and Inventory System CWE-89 7.3 High 2026-05-01
CVE-2026-7549 SourceCodester Pharmacy Sales and Inventory System ajax.php delete_customer sql injection — Pharmacy Sales and Inventory System CWE-89 7.3 High 2026-05-01
CVE-2026-7545 SourceCodester Advanced School Management System checkEmail Endpoint commonController.php sql injection — Advanced School Management System CWE-89 7.3 High 2026-05-01
CVE-2026-7506 SourceCodester Hotel Management System check sql injection — Hotel Management System CWE-89 7.3 High 2026-04-30
CVE-2026-7447 SourceCodester Pet Grooming Management Software update_customer.php sql injection — Pet Grooming Management Software CWE-89 6.3 Medium 2026-04-30
CVE-2026-7410 SourceCodester Pizzafy Ecommerce System ajax.php add_to_cart sql injection — Pizzafy Ecommerce System CWE-89 6.3 Medium 2026-04-29
CVE-2026-7409 SourceCodester Pizzafy Ecommerce System ajax.php save_user sql injection — Pizzafy Ecommerce System CWE-89 4.7 Medium 2026-04-29
CVE-2026-7408 SourceCodester Pizzafy Ecommerce System ajax.php save_menu sql injection — Pizzafy Ecommerce System CWE-89 4.7 Medium 2026-04-29
CVE-2026-7407 SourceCodester Pizzafy Ecommerce System Setting ajax.php save_settings sql injection — Pizzafy Ecommerce System CWE-89 4.7 Medium 2026-04-29
CVE-2026-7401 SourceCodester CET Automated Grading System with AI Predictive Analytics Registration index.php register cross site scripting — CET Automated Grading System with AI Predictive Analytics CWE-79 4.3 Medium 2026-04-29
CVE-2026-7394 SourceCodester Pizzafy Ecommerce System GET Parameter view_order.php sql injection — Pizzafy Ecommerce System CWE-89 4.7 Medium 2026-04-29
CVE-2026-7393 SourceCodester Pizzafy Ecommerce System File Extension admin_class_novo.php save_menu unrestricted upload — Pizzafy Ecommerce System CWE-434 4.7 Medium 2026-04-29
CVE-2026-7392 SourceCodester Pharmacy Sales and Inventory System ajax.php delete_supplier sql injection — Pharmacy Sales and Inventory System CWE-89 6.3 Medium 2026-04-29
CVE-2026-7391 SourceCodester Pharmacy Sales and Inventory System ajax.php save_supplier sql injection — Pharmacy Sales and Inventory System CWE-89 6.3 Medium 2026-04-29
CVE-2026-7390 SourceCodester Pharmacy Sales and Inventory System index.php customer cross site scripting — Pharmacy Sales and Inventory System CWE-79 3.5 Low 2026-04-29

This page lists every published CVE security advisory associated with SourceCodester. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.