Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SourceCodester — Vulnerabilities & Security Advisories 1910

Browse all 1910 CVE security advisories affecting SourceCodester. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SourceCodester operates as a repository for free and premium source code, scripts, and web applications, primarily serving developers seeking ready-made solutions for rapid deployment. This business model inherently exposes users to significant security risks, as the platform hosts thousands of projects with varying levels of code review. Historically, vulnerabilities found in these downloads frequently include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from outdated frameworks or unpatched dependencies. Privilege escalation flaws are also common, allowing attackers to bypass authentication mechanisms. While SourceCodester does not typically manage post-download security patches, the sheer volume of recorded CVEs highlights systemic issues in code quality assurance. Users relying on these resources must perform rigorous independent security audits, as the platform’s primary focus remains distribution rather than comprehensive vulnerability management or remediation support.

CVE IDTitleCVSSSeverityPublished
CVE-2026-16155 SourceCodester Class and Exam Timetabling System schoolyr.php cross site scripting — Class and Exam Timetabling SystemCWE-79 3.5 Low2026-07-18
CVE-2026-16154 SourceCodester Class and Exam Timetabling System edit_room1.php sql injection — Class and Exam Timetabling SystemCWE-89 7.3 High2026-07-18
CVE-2026-16152 SourceCodester Class and Exam Timetabling System edit_rooma.php sql injection — Class and Exam Timetabling SystemCWE-89 7.3 High2026-07-18
CVE-2026-15715 SourceCodester Class and Exam Timetabling System exam.php cross site scripting — Class and Exam Timetabling SystemCWE-79 4.3 Medium2026-07-14
CVE-2026-15703 SourceCodester Simple and Nice Shopping Cart Script userproductdeletequery.php sql injection — Simple and Nice Shopping Cart ScriptCWE-89 7.3 High2026-07-14
CVE-2026-15597 SourceCodester Class and Exam Timetabling System edit_exam2.php sql injection — Class and Exam Timetabling SystemCWE-89 7.3 High2026-07-13
CVE-2026-15596 SourceCodester Class and Exam Timetabling System subject.php cross site scripting — Class and Exam Timetabling SystemCWE-79 4.3 Medium2026-07-13
CVE-2026-15595 SourceCodester Class and Exam Timetabling System forsubject.php cross site scripting — Class and Exam Timetabling SystemCWE-79 4.3 Medium2026-07-13
CVE-2026-15540 SourceCodester Online Book Store System Administrative index.php php file inclusion — Online Book Store SystemCWE-98 4.3 Medium2026-07-13
CVE-2026-15539 SourceCodester Online Book Store System Book Image Upload Feature index.php books unrestricted upload — Online Book Store SystemCWE-434 4.7 Medium2026-07-13
CVE-2026-15537 SourceCodester Online Book Store System login.php sql injection — Online Book Store SystemCWE-89 7.3 High2026-07-13
CVE-2026-15532 SourceCodester Online Book Store System User Management cross site scripting — Online Book Store SystemCWE-79 2.4 Low2026-07-13
CVE-2026-15190 SourceCodester Simple and Nice Shopping Cart Script login.php sql injection — Simple and Nice Shopping Cart ScriptCWE-89 7.3 High2026-07-09
CVE-2026-14778 SourceCodester Onlne Examination & Learning Management System Enrollment Management ajax_enroll.php improper authorization — Onlne Examination & Learning Management SystemCWE-285 7.3 High2026-07-05
CVE-2026-14777 SourceCodester Onlne Examination & Learning Management System announcements.php unrestricted upload — Onlne Examination & Learning Management SystemCWE-434 6.3 Medium2026-07-05
CVE-2026-14776 SourceCodester Onlne Examination & Learning Management System Filename Extension upload_files.php pathinfo unrestricted upload — Onlne Examination & Learning Management SystemCWE-434 6.3 Medium2026-07-05
CVE-2026-14775 SourceCodester Onlne Examination & Learning Management System process_lesson.php unrestricted upload — Onlne Examination & Learning Management SystemCWE-434 6.3 Medium2026-07-05
CVE-2026-14772 SourceCodester Class and Exam Timetabling System edit_course1.php sql injection — Class and Exam Timetabling SystemCWE-89 7.3 High2026-07-05
CVE-2026-14771 SourceCodester Class and Exam Timetabling System edit_exam1.php sql injection — Class and Exam Timetabling SystemCWE-89 7.3 High2026-07-05
CVE-2026-14770 SourceCodester Class and Exam Timetabling System edit_room.php sql injection — Class and Exam Timetabling SystemCWE-89 7.3 High2026-07-05
CVE-2026-14734 SourceCodester Class and Exam Timetabling System edit_product.php sql injection — Class and Exam Timetabling SystemCWE-89 7.3 High2026-07-05
CVE-2026-14733 SourceCodester Class and Exam Timetabling System edit_coursea.php sql injection — Class and Exam Timetabling SystemCWE-89 7.3 High2026-07-05
CVE-2026-14732 SourceCodester Class and Exam Timetabling System edit_exam.php sql injection — Class and Exam Timetabling SystemCWE-89 7.3 High2026-07-05
CVE-2026-14725 SourceCodester Online Boat Reservation System session expiration — Online Boat Reservation SystemCWE-613 6.3 Medium2026-07-05
CVE-2026-14719 SourceCodester Onlne Examination & Learning Management System Registration Endpoint register.php privileges management — Onlne Examination & Learning Management SystemCWE-269 7.3 High2026-07-05
CVE-2026-14713 SourceCodester Pizzafy E-Commerce System ajax.php confirm_order sql injection — Pizzafy E-Commerce SystemCWE-89 7.3 High2026-07-05
CVE-2026-14698 SourceCodester Syllabus-Aligned Learning Management and Examination System upload_files.php unrestricted upload — Syllabus-Aligned Learning Management and Examination SystemCWE-434 6.3 Medium2026-07-05
CVE-2026-14695 SourceCodester Multi-Vendor Online Grocery Management System Registration Users.php save_client sql injection — Multi-Vendor Online Grocery Management SystemCWE-89 7.3 High2026-07-05
CVE-2026-14694 SourceCodester Multi-Vendor Online Grocery Management System POST Parameter Master.php cancel_order sql injection — Multi-Vendor Online Grocery Management SystemCWE-89 6.3 Medium2026-07-05
CVE-2026-14693 SourceCodester Multi-Vendor Online Grocery Management System Master.php cancel_order improper authorization — Multi-Vendor Online Grocery Management SystemCWE-285 5.4 Medium2026-07-05

This page lists every published CVE security advisory associated with SourceCodester. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.