Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

itsourcecode — Vulnerabilities & Security Advisories 574

Browse all 574 CVE security advisories affecting itsourcecode. AI-powered Chinese analysis, POCs, and references for each vulnerability.

ItsSourceCode operates as a repository for pre-built source code and software projects, primarily targeting students and developers seeking ready-made solutions for academic or commercial applications. This business model inherently distributes complex, often unvetted codebases that frequently contain significant security flaws. Historical analysis reveals a high prevalence of critical vulnerability classes, including Remote Code Execution (RCE), Cross-Site Scripting (XSS), and SQL Injection, stemming from inadequate input validation and insecure default configurations. The platform’s lack of rigorous security auditing allows these defects to persist, creating a widespread attack surface for downstream users. With over 503 CVEs currently recorded, the site serves as a notable vector for exploiting known weaknesses in popular frameworks. Major incidents involve the distribution of compromised templates that facilitate unauthorized access and data exfiltration, highlighting the risks associated with sourcing unverified software components from third-party aggregators without proper security review.

CVE IDTitleCVSSSeverityPublished
CVE-2025-10068 itsourcecode Online Discussion Forum add_views.php sql injection — Online Discussion ForumCWE-89 7.3 High2025-09-07
CVE-2025-10067 itsourcecode POS Point of Sale System empty_table.php cross site scripting — POS Point of Sale SystemCWE-79 4.3 Medium2025-09-07
CVE-2025-10066 itsourcecode POS Point of Sale System dymanic_table.php cross site scripting — POS Point of Sale SystemCWE-79 4.3 Medium2025-09-07
CVE-2025-10065 itsourcecode POS Point of Sale System dom_data_th.php cross site scripting — POS Point of Sale SystemCWE-79 4.3 Medium2025-09-07
CVE-2025-10064 itsourcecode POS Point of Sale System dom_data_two_headers.php cross site scripting — POS Point of Sale SystemCWE-79 4.3 Medium2025-09-07
CVE-2025-10063 itsourcecode POS Point of Sale System deferred_table.php cross site scripting — POS Point of Sale SystemCWE-79 4.3 Medium2025-09-06
CVE-2025-10062 itsourcecode Student Information Management System login.php sql injection — Student Information Management SystemCWE-89 7.3 High2025-09-06
CVE-2025-10033 itsourcecode Online Discussion Forum admin sql injection — Online Discussion ForumCWE-89 7.3 High2025-09-06
CVE-2025-10029 itsourcecode POS Point of Sale System complex_header_2.php cross site scripting — POS Point of Sale SystemCWE-79 3.5 Low2025-09-06
CVE-2025-10028 itsourcecode POS Point of Sale System 6776.php cross site scripting — POS Point of Sale SystemCWE-79 3.5 Low2025-09-06
CVE-2025-10027 itsourcecode POS Point of Sale System 2512.php cross site scripting — POS Point of Sale SystemCWE-79 3.5 Low2025-09-05
CVE-2025-10026 itsourcecode POS Point of Sale System -complex_header.php cross site scripting — POS Point of Sale SystemCWE-79 3.5 Low2025-09-05
CVE-2025-9840 itsourcecode Sports Management System gametype.php sql injection — Sports Management SystemCWE-89 6.3 Medium2025-09-02
CVE-2025-9839 itsourcecode Student Information Management System index.php sql injection — Student Information Management SystemCWE-89 7.3 High2025-09-02
CVE-2025-9838 itsourcecode Student Information Management System index.php sql injection — Student Information Management SystemCWE-89 7.3 High2025-09-02
CVE-2025-9837 itsourcecode Student Information Management System index.php sql injection — Student Information Management SystemCWE-89 7.3 High2025-09-02
CVE-2025-9793 itsourcecode Apartment Management System Setting admin.php sql injection — Apartment Management SystemCWE-89 7.3 High2025-09-01
CVE-2025-9792 itsourcecode Apartment Management System e_all_info.php sql injection — Apartment Management SystemCWE-89 7.3 High2025-09-01
CVE-2025-9768 itsourcecode Sports Management System mode.php sql injection — Sports Management SystemCWE-89 6.3 Medium2025-09-01
CVE-2025-9767 itsourcecode Sports Management System sporttype.php sql injection — Sports Management SystemCWE-89 7.3 High2025-09-01
CVE-2025-9766 itsourcecode Sports Management System facilitator.php sql injection — Sports Management SystemCWE-89 7.3 High2025-09-01
CVE-2025-9765 itsourcecode Sports Management System tournament_details.php sql injection — Sports Management SystemCWE-89 7.3 High2025-09-01
CVE-2025-9764 itsourcecode Sports Management System resultdetails.php sql injection — Sports Management SystemCWE-89 7.3 High2025-09-01
CVE-2025-9730 itsourcecode Apartment Management System updateProfile.php sql injection — Apartment Management SystemCWE-89 7.3 High2025-08-31
CVE-2025-9679 itsourcecode Student Information System course_edit1.php sql injection — Student Information SystemCWE-89 7.3 High2025-08-30
CVE-2025-9645 itsourcecode Apartment Management System r_all_info.php sql injection — Apartment Management SystemCWE-89 7.3 High2025-08-29
CVE-2025-9644 itsourcecode Apartment Management System bill_setup.php sql injection — Apartment Management SystemCWE-89 7.3 High2025-08-29
CVE-2025-9643 itsourcecode Apartment Management System utility_bill_setup.php sql injection — Apartment Management SystemCWE-89 7.3 High2025-08-29
CVE-2025-9601 itsourcecode Apartment Management System employee_salary_setup.php sql injection — Apartment Management SystemCWE-89 7.3 High2025-08-29
CVE-2025-9600 itsourcecode Apartment Management System member_type_setup.php sql injection — Apartment Management SystemCWE-89 7.3 High2025-08-29

This page lists every published CVE security advisory associated with itsourcecode. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.