Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

code-projects — Vulnerabilities & Security Advisories 1305

Browse all 1305 CVE security advisories affecting code-projects. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Code-projects is a software development platform primarily serving as a repository for user-generated code snippets, tutorials, and project files. Historically, the platform has been associated with a significant volume of security vulnerabilities, currently totaling 1238 CVEs. These flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation issues, often stemming from insecure handling of uploaded files or inadequate input validation within user-submitted scripts. The high number of recorded vulnerabilities suggests systemic weaknesses in the platform’s code review and deployment processes, allowing malicious actors to exploit exposed endpoints. While specific major incidents are rarely publicized as widespread breaches, the sheer quantity of CVEs indicates a persistent risk for users downloading and executing unverified code from the site. This environment necessitates rigorous sandboxing and verification practices for any developer interacting with the platform’s resources.

CVE IDTitleCVSSSeverityPublished
CVE-2025-0301 code-projects Online Book Shop subcat.php cross site scripting — Online Book ShopCWE-79 3.5 Low2025-01-07
CVE-2025-0300 code-projects Online Book Shop subcat.php sql injection — Online Book ShopCWE-89 6.3 Medium2025-01-07
CVE-2025-0299 code-projects Online Book Shop search_result.php sql injection — Online Book ShopCWE-89 6.3 Medium2025-01-07
CVE-2025-0298 code-projects Online Book Shop process_login.php sql injection — Online Book ShopCWE-89 6.3 Medium2025-01-07
CVE-2025-0297 code-projects Online Book Shop detail.php sql injection — Online Book ShopCWE-89 6.3 Medium2025-01-07
CVE-2025-0296 code-projects Online Book Shop booklist.php sql injection — Online Book ShopCWE-89 6.3 Medium2025-01-07
CVE-2025-0295 code-projects Online Book Shop booklist.php cross site scripting — Online Book ShopCWE-79 3.5 Low2025-01-07
CVE-2025-0230 code-projects Responsive Hotel Site print.php sql injection — Responsive Hotel SiteCWE-89 6.3 Medium2025-01-05
CVE-2025-0229 code-projects Travel Management System enquiry.php sql injection — Travel Management SystemCWE-89 6.3 Medium2025-01-05
CVE-2025-0228 code-projects Local Storage Todo App index.html cross site scripting — Local Storage Todo AppCWE-79 2.4 Low2025-01-05
CVE-2025-0208 code-projects Online Shoe Store summary.php sql injection — Online Shoe StoreCWE-89 6.3 Medium2025-01-04
CVE-2025-0207 code-projects Online Shoe Store login.php sql injection — Online Shoe StoreCWE-89 7.3 High2025-01-04
CVE-2025-0206 code-projects Online Shoe Store index.php access control — Online Shoe StoreCWE-284 5.3 Medium2025-01-04
CVE-2025-0205 code-projects Online Shoe Store details2.php sql injection — Online Shoe StoreCWE-89 6.3 Medium2025-01-04
CVE-2025-0204 code-projects Online Shoe Store details.php sql injection — Online Shoe StoreCWE-89 6.3 Medium2025-01-04
CVE-2025-0203 code-projects Student Management System DbFunction.php showSubject1 sql injection — Student Management SystemCWE-89 6.3 Medium2025-01-04
CVE-2025-0201 code-projects Point of Sales and Inventory Management System update_account.php sql injection — Point of Sales and Inventory Management SystemCWE-89 6.3 Medium2025-01-04
CVE-2025-0200 code-projects Point of Sales and Inventory Management System search_num.php sql injection — Point of Sales and Inventory Management SystemCWE-89 6.3 Medium2025-01-04
CVE-2025-0199 code-projects Point of Sales and Inventory Management System minus_cart.php sql injection — Point of Sales and Inventory Management SystemCWE-89 6.3 Medium2025-01-03
CVE-2025-0198 code-projects Point of Sales and Inventory Management System search_result.php sql injection — Point of Sales and Inventory Management SystemCWE-89 6.3 Medium2025-01-03
CVE-2025-0197 code-projects Point of Sales and Inventory Management System search.php sql injection — Point of Sales and Inventory Management SystemCWE-89 6.3 Medium2025-01-03
CVE-2025-0196 code-projects Point of Sales and Inventory Management System plist.php sql injection — Point of Sales and Inventory Management SystemCWE-89 6.3 Medium2025-01-03
CVE-2025-0195 code-projects Point of Sales and Inventory Management System del_product.php sql injection — Point of Sales and Inventory Management SystemCWE-89 6.3 Medium2025-01-03
CVE-2025-0176 code-projects Point of Sales and Inventory Management System add_cart.php sql injection — Point of Sales and Inventory Management SystemCWE-89 6.3 Medium2025-01-03
CVE-2025-0175 code-projects Online Shop view.php cross site scripting — Online ShopCWE-79 3.5 Low2025-01-03
CVE-2025-0174 code-projects Point of Sales and Inventory Management System Parameter search_result2.php sql injection — Point of Sales and Inventory Management SystemCWE-89 6.3 Medium2025-01-03
CVE-2025-0172 code-projects Chat System deleteroom.php sql injection — Chat SystemCWE-89 6.3 Medium2025-01-02
CVE-2025-0171 code-projects Chat System deleteuser.php sql injection — Chat SystemCWE-89 6.3 Medium2025-01-02
CVE-2024-13093 code-projects Job Recruitment Seeker Profile _call_main_search_ajax.php sql injection — Job RecruitmentCWE-89 6.3 Medium2025-01-02
CVE-2024-13092 code-projects Job Recruitment Job Post search_ajax.php sql injection — Job RecruitmentCWE-89 6.3 Medium2025-01-02

This page lists every published CVE security advisory associated with code-projects. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.