Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

code-projects — Vulnerabilities & Security Advisories 1305

Browse all 1305 CVE security advisories affecting code-projects. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Code-projects is a software development platform primarily serving as a repository for user-generated code snippets, tutorials, and project files. Historically, the platform has been associated with a significant volume of security vulnerabilities, currently totaling 1238 CVEs. These flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation issues, often stemming from insecure handling of uploaded files or inadequate input validation within user-submitted scripts. The high number of recorded vulnerabilities suggests systemic weaknesses in the platform’s code review and deployment processes, allowing malicious actors to exploit exposed endpoints. While specific major incidents are rarely publicized as widespread breaches, the sheer quantity of CVEs indicates a persistent risk for users downloading and executing unverified code from the site. This environment necessitates rigorous sandboxing and verification practices for any developer interacting with the platform’s resources.

CVE IDTitleCVSSSeverityPublished
CVE-2025-6906 code-projects Car Rental System login.php sql injection — Car Rental SystemCWE-89 7.3 High2025-06-30
CVE-2025-6905 code-projects Car Rental System signup.php sql injection — Car Rental SystemCWE-89 7.3 High2025-06-30
CVE-2025-6904 code-projects Car Rental System add_cars.php sql injection — Car Rental SystemCWE-89 7.3 High2025-06-30
CVE-2025-6903 code-projects Car Rental System approve.php sql injection — Car Rental SystemCWE-89 7.3 High2025-06-30
CVE-2025-6902 code-projects Inventory Management System editUser.php sql injection — Inventory Management SystemCWE-89 7.3 High2025-06-30
CVE-2025-6901 code-projects Inventory Management System removeUser.php sql injection — Inventory Management SystemCWE-89 7.3 High2025-06-30
CVE-2025-6900 code-projects Library System add-book.php unrestricted upload — Library SystemCWE-434 6.3 Medium2025-06-30
CVE-2025-6891 code-projects Inventory Management System createUser.php sql injection — Inventory Management SystemCWE-89 7.3 High2025-06-30
CVE-2025-6890 code-projects Movie Ticketing System ticketConfirmation.php sql injection — Movie Ticketing SystemCWE-89 6.3 Medium2025-06-30
CVE-2025-6889 code-projects Movie Ticketing System logIn.php sql injection — Movie Ticketing SystemCWE-89 7.3 High2025-06-30
CVE-2025-6884 code-projects Staff Audit System search_index.php sql injection — Staff Audit SystemCWE-89 6.3 Medium2025-06-30
CVE-2025-6883 code-projects Staff Audit System update_index.php sql injection — Staff Audit SystemCWE-89 6.3 Medium2025-06-30
CVE-2025-6866 code-projects Simple Forum forum_downloadfile.php path traversal — Simple ForumCWE-22 4.3 Medium2025-06-29
CVE-2025-6850 code-projects Simple Forum forum1.php sql injection — Simple ForumCWE-89 6.3 Medium2025-06-29
CVE-2025-6849 code-projects Simple Forum forum_edit1.php cross site scripting — Simple ForumCWE-79 3.5 Low2025-06-29
CVE-2025-6848 code-projects Simple Forum forum1.php unrestricted upload — Simple ForumCWE-434 6.3 Medium2025-06-29
CVE-2025-6847 code-projects Simple Forum forum_edit.php sql injection — Simple ForumCWE-89 6.3 Medium2025-06-29
CVE-2025-6846 code-projects Simple Forum forum_viewfile.php sql injection — Simple ForumCWE-89 7.3 High2025-06-29
CVE-2025-6845 code-projects Simple Forum register1.php sql injection — Simple ForumCWE-89 7.3 High2025-06-29
CVE-2025-6844 code-projects Simple Forum signin.php sql injection — Simple ForumCWE-89 7.3 High2025-06-29
CVE-2025-6843 code-projects Simple Photo Gallery upload-photo.php unrestricted upload — Simple Photo GalleryCWE-434 7.3 High2025-06-29
CVE-2025-6842 code-projects Product Inventory System edit_user.php sql injection — Product Inventory SystemCWE-89 4.7 Medium2025-06-29
CVE-2025-6841 code-projects Product Inventory System edit_product.php sql injection — Product Inventory SystemCWE-89 4.7 Medium2025-06-29
CVE-2025-6840 code-projects Product Inventory System Login index.php sql injection — Product Inventory SystemCWE-89 7.3 High2025-06-29
CVE-2025-6837 code-projects Library System profile.php unrestricted upload — Library SystemCWE-434 6.3 Medium2025-06-29
CVE-2025-6836 code-projects Library System profile.php sql injection — Library SystemCWE-89 7.3 High2025-06-29
CVE-2025-6835 code-projects Library System student-issue-book.php sql injection — Library SystemCWE-89 7.3 High2025-06-29
CVE-2025-6834 code-projects Inventory Management System editPayment.php sql injection — Inventory Management SystemCWE-89 7.3 High2025-06-28
CVE-2025-6828 code-projects Inventory Management System orders.php sql injection — Inventory Management SystemCWE-89 7.3 High2025-06-28
CVE-2025-6827 code-projects Inventory Management System editOrder.php sql injection — Inventory Management SystemCWE-89 7.3 High2025-06-28

This page lists every published CVE security advisory associated with code-projects. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.