Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

SourceCodester — Vulnerabilities & Security Advisories 1769

Browse all 1769 CVE security advisories affecting SourceCodester. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SourceCodester operates as a repository for free and premium source code, scripts, and web applications, primarily serving developers seeking ready-made solutions for rapid deployment. This business model inherently exposes users to significant security risks, as the platform hosts thousands of projects with varying levels of code review. Historically, vulnerabilities found in these downloads frequently include Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, often stemming from outdated frameworks or unpatched dependencies. Privilege escalation flaws are also common, allowing attackers to bypass authentication mechanisms. While SourceCodester does not typically manage post-download security patches, the sheer volume of recorded CVEs highlights systemic issues in code quality assurance. Users relying on these resources must perform rigorous independent security audits, as the platform’s primary focus remains distribution rather than comprehensive vulnerability management or remediation support.

CVE IDTitleCVSSSeverityPublished
CVE-2023-1592 SourceCodester Automatic Question Paper Generator System GET Parameter view_class.php sql injection — Automatic Question Paper Generator SystemCWE-89 6.3 Medium2023-03-23
CVE-2023-1591 SourceCodester Automatic Question Paper Generator System sql injection — Automatic Question Paper Generator SystemCWE-89 6.3 Medium2023-03-23
CVE-2023-1590 SourceCodester Online Tours & Travels Management System currency.php exec sql injection — Online Tours & Travels Management SystemCWE-89 6.3 Medium2023-03-23
CVE-2023-1589 SourceCodester Online Tours & Travels Management System approve_delete.php exec sql injection — Online Tours & Travels Management SystemCWE-89 6.3 Medium2023-03-23
CVE-2023-1569 SourceCodester E-Commerce System cross site scripting — E-Commerce SystemCWE-79 3.5 Low2023-03-22
CVE-2023-1568 SourceCodester Student Study Center Desk Management System GET Parameter index.php cross site scripting — Student Study Center Desk Management SystemCWE-79 3.5 Low2023-03-22
CVE-2023-1567 SourceCodester Student Study Center Desk Management System assign.php cross site scripting — Student Study Center Desk Management SystemCWE-79 3.5 Low2023-03-22
CVE-2023-1566 SourceCodester Medical Certificate Generator App action.php sql injection — Medical Certificate Generator AppCWE-89 6.3 Medium2023-03-22
CVE-2023-1564 SourceCodester Air Cargo Management System GET Parameter update_status.php sql injection — Air Cargo Management SystemCWE-89 6.3 Medium2023-03-22
CVE-2023-1563 SourceCodester Student Study Center Desk Management System assign.php sql injection — Student Study Center Desk Management SystemCWE-89 6.3 Medium2023-03-22
CVE-2023-1559 SourceCodester Storage Unit Rental Management System unrestricted upload — Storage Unit Rental Management SystemCWE-434 4.7 Medium2023-03-22
CVE-2023-1557 SourceCodester E-Commerce System Username access control — E-Commerce SystemCWE-284 6.3 Medium2023-03-22
CVE-2023-1556 SourceCodester Judging Management System summary_results.php sql injection — Judging Management SystemCWE-89 6.3 Medium2023-03-22
CVE-2023-1507 SourceCodester E-Commerce System Category Name controller.php cross site scripting — E-Commerce SystemCWE-79 3.5 Low2023-03-20
CVE-2023-1506 SourceCodester E-Commerce System login.php sql injection — E-Commerce SystemCWE-89 5.6 Medium2023-03-20
CVE-2023-1505 SourceCodester E-Commerce System setDiscount.php sql injection — E-Commerce SystemCWE-89 5.0 Medium2023-03-20
CVE-2023-1504 SourceCodester Alphaware Simple E-Commerce System sql injection — Alphaware Simple E-Commerce SystemCWE-89 5.6 Medium2023-03-20
CVE-2023-1503 SourceCodester Alphaware Simple E-Commerce System admin_index.php sql injection — Alphaware Simple E-Commerce SystemCWE-89 5.6 Medium2023-03-20
CVE-2023-1502 SourceCodester Alphaware Simple E-Commerce System edit_customer.php sql injection — Alphaware Simple E-Commerce SystemCWE-89 5.6 Medium2023-03-20
CVE-2023-1497 SourceCodester Simple and Nice Shopping Cart Script uploaderm.php unrestricted upload — Simple and Nice Shopping Cart ScriptCWE-434 6.3 Medium2023-03-19
CVE-2023-1485 SourceCodester Young Entrepreneur E-Negosyo System GET Parameter index.php cross site scripting — Young Entrepreneur E-Negosyo SystemCWE-79 3.5 Low2023-03-18
CVE-2023-1481 SourceCodester Monitoring of Students Cyber Accounts System POST Parameter cross site scripting — Monitoring of Students Cyber Accounts SystemCWE-79 3.5 Low2023-03-18
CVE-2023-1480 SourceCodester Monitoring of Students Cyber Accounts System POST Parameter login.php sql injection — Monitoring of Students Cyber Accounts SystemCWE-89 6.3 Medium2023-03-18
CVE-2023-1479 SourceCodester Simple Music Player save_music.php unrestricted upload — Simple Music PlayerCWE-434 6.3 Medium2023-03-18
CVE-2023-1475 SourceCodester Canteen Management System createuser.php query sql injection — Canteen Management SystemCWE-89 6.3 Medium2023-03-17
CVE-2023-1474 SourceCodester Automatic Question Paper Generator System GET Parameter manage_question_paper.php sql injection — Automatic Question Paper Generator SystemCWE-89 6.3 Medium2023-03-17
CVE-2023-1468 SourceCodester Student Study Center Desk Management System Report sql injection — Student Study Center Desk Management SystemCWE-89 6.3 Medium2023-03-17
CVE-2023-1467 SourceCodester Student Study Center Desk Management System POST Parameter path traversal — Student Study Center Desk Management SystemCWE-22 6.5 Medium2023-03-17
CVE-2023-1466 SourceCodester Student Study Center Desk Management System view_student sql injection — Student Study Center Desk Management SystemCWE-89 6.3 Medium2023-03-17
CVE-2023-1464 SourceCodester Medicine Tracker System improper authentication — Medicine Tracker SystemCWE-287 7.3 High2023-03-17

This page lists every published CVE security advisory associated with SourceCodester. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.