Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

code-projects — Vulnerabilities & Security Advisories 1240

Browse all 1240 CVE security advisories affecting code-projects. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Code-projects is a software development platform primarily serving as a repository for user-generated code snippets, tutorials, and project files. Historically, the platform has been associated with a significant volume of security vulnerabilities, currently totaling 1238 CVEs. These flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation issues, often stemming from insecure handling of uploaded files or inadequate input validation within user-submitted scripts. The high number of recorded vulnerabilities suggests systemic weaknesses in the platform’s code review and deployment processes, allowing malicious actors to exploit exposed endpoints. While specific major incidents are rarely publicized as widespread breaches, the sheer quantity of CVEs indicates a persistent risk for users downloading and executing unverified code from the site. This environment necessitates rigorous sandboxing and verification practices for any developer interacting with the platform’s resources.

CVE IDTitleCVSSSeverityPublished
CVE-2026-8125 code-projects Simple Chat System sendMessage.php sql injection — Simple Chat SystemCWE-89 6.3 Medium2026-05-08
CVE-2026-8098 code-projects Feedback System checklogin.php sql injection — Feedback SystemCWE-89 7.3 High2026-05-07
CVE-2026-7732 code-projects BloodBank Managing System request_blood.php unrestricted upload — BloodBank Managing SystemCWE-434 6.3 Medium2026-05-04
CVE-2026-7731 code-projects BloodBank Managing System get_state.php sql injection — BloodBank Managing SystemCWE-89 6.3 Medium2026-05-04
CVE-2026-7716 code-projects Gym Management System In PHP/Windows NT index.php sql injection — Gym Management System In PHPCWE-89 6.3 Medium2026-05-04
CVE-2026-7632 code-projects Online Hospital Management System viewappointment.php sql injection — Online Hospital Management SystemCWE-89 7.3 High2026-05-02
CVE-2026-7631 code-projects Online Hospital Management System Registration improper authorization — Online Hospital Management SystemCWE-285 5.4 Medium2026-05-02
CVE-2026-7553 code-projects Gym Management System edit_exercises.php sql injection — Gym Management SystemCWE-89 4.7 Medium2026-05-01
CVE-2026-7503 code-projects for Plugin cstecgi.cgi setWiFiMultipleConfig buffer overflow — for PluginCWE-120 8.8 High2026-04-30
CVE-2026-7238 code-projects Online Music Site AdminUpdateAlbum.php unrestricted upload — Online Music SiteCWE-434 4.7 Medium2026-04-28
CVE-2026-7229 code-projects Coaching Management System POST reply.php sql injection — Coaching Management SystemCWE-89 6.3 Medium2026-04-28
CVE-2026-7222 code-projects Coaching Management System Complaint Form complaint.php cross site scripting — Coaching Management SystemCWE-79 3.5 Low2026-04-28
CVE-2026-7134 code-projects Online Lot Reservation System edithousepic.php unrestricted upload — Online Lot Reservation SystemCWE-434 4.7 Medium2026-04-27
CVE-2026-7133 code-projects Online Lot Reservation System activity.php unrestricted upload — Online Lot Reservation SystemCWE-434 4.7 Medium2026-04-27
CVE-2026-7132 code-projects Online Lot Reservation System download.php readfile path traversal — Online Lot Reservation SystemCWE-22 5.3 Medium2026-04-27
CVE-2026-7131 code-projects Online Lot Reservation System loginuser.php sql injection — Online Lot Reservation SystemCWE-89 7.3 High2026-04-27
CVE-2026-7118 code-projects Employee Management System cancel.php sql injection — Employee Management SystemCWE-89 6.3 Medium2026-04-27
CVE-2026-7117 code-projects Employee Management System approve.php sql injection — Employee Management SystemCWE-89 6.3 Medium2026-04-27
CVE-2026-7116 code-projects Employee Management System mark.php cross site scripting — Employee Management SystemCWE-79 4.3 Medium2026-04-27
CVE-2026-7115 code-projects Employee Management System delete.php sql injection — Employee Management SystemCWE-89 6.3 Medium2026-04-27
CVE-2026-7114 code-projects Employee Management System edit.php sql injection — Employee Management SystemCWE-89 6.3 Medium2026-04-27
CVE-2026-7110 code-projects Invoice System in Laravel item cross site scripting — Invoice System in LaravelCWE-79 3.5 Low2026-04-27
CVE-2026-7109 code-projects Invoice System in Laravel API Endpoint item improper authorization — Invoice System in LaravelCWE-285 5.3 Medium2026-04-27
CVE-2026-7108 code-projects Invoice System in Laravel cross-site request forgery — Invoice System in LaravelCWE-352 4.3 Medium2026-04-27
CVE-2026-7107 code-projects Invoice System in Laravel company unrestricted upload — Invoice System in LaravelCWE-434 6.3 Medium2026-04-27
CVE-2026-7103 code-projects Chat System MD5 Hash update_user.php weak hash — Chat SystemCWE-328 3.7 Low2026-04-27
CVE-2026-7095 code-projects Employee Management System edit.php cross site scripting — Employee Management SystemCWE-79 4.3 Medium2026-04-27
CVE-2026-7093 code-projects Invoice System in Laravel Invoice Endpoint invoice improper authorization — Invoice System in LaravelCWE-285 6.3 Medium2026-04-27
CVE-2026-7092 code-projects Invoice System in Laravel Profile profile improper authorization — Invoice System in LaravelCWE-285 6.3 Medium2026-04-27
CVE-2026-7091 code-projects Invoice System in Laravel User Management user improper authorization — Invoice System in LaravelCWE-285 6.3 Medium2026-04-27

This page lists every published CVE security advisory associated with code-projects. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.