SourceCodester: 18 SQLi and Other Flaws Disclosed in Batch, Exploits Publicly Available
Eighteen vulnerabilities, many critical SQL injection flaws, were disclosed across multiple SourceCodester products from August 13-19, 2026, with publicly available exploits.

Key findings
- A batch of 18 vulnerabilities was disclosed for SourceCodester products between August 13-19, 2026.
- Multiple SQL injection vulnerabilities were found across several applications, including Simple Online Food Ordering System and Class and Exam Timetabling System.
- High-severity SQL injection flaws (CVSSv3 7.3) were prevalent, with exploits publicly disclosed.
- Other vulnerability types include CSRF, XSS, directory listing, file accessibility, and unrestricted uploads.
- The vulnerabilities affect a range of SourceCodester systems, highlighting a need for prompt updates.
On August 13-19, 2026, a batch of 18 vulnerabilities was disclosed across multiple SourceCodester products, with a significant number of these flaws leading to SQL injection. The vulnerabilities affect various systems including the Simple Online Food Ordering System, Class and Exam Timetabling System, and Simple Student Information System, among others. The widespread nature of these SQL injection flaws, often found in files like ajax.php and edit_subject.php, indicates a potential systemic issue in how these applications handle user input. The disclosed vulnerabilities carry a severity ranging from Low to High, with many High-severity SQL injection flaws (CVSSv3 7.3) being publicly disclosed and potentially exploitable.
Several of the disclosed vulnerabilities are SQL injection flaws, primarily affecting systems like the Simple Online Food Ordering System (CVE-2026-76050, CVE-2026-76049, CVE-2026-76048), Class and Exam Timetabling System (CVE-2026-75080, CVE-2026-75079, CVE-2026-19899), and others such as Pet Grooming Management Software (CVE-2026-75014), Stock Management System (CVE-2026-19925), Simple Client Management System (CVE-2026-19825), Air Cargo Management System (CVE-2026-19787), and Simple Student Information System (CVE-2026-19710). These SQL injection vulnerabilities often stem from the manipulation of an 'ID' argument in various PHP files, allowing remote attackers to inject malicious SQL code.
Beyond SQL injection, other vulnerabilities include Cross-Site Request Forgery (CSRF) in the Online Examination & Learning Management System (CVE-2026-75151), Cross-Site Scripting (XSS) in the Class and Exam Timetabling System (CVE-2026-75078, CVE-2026-75077) and the Online Book Store System (CVE-2026-19904). Additionally, directory listing vulnerabilities were found in the Best Employee Management System (CVE-2026-10987), file/directory accessibility issues in the Online Clothing Store (CVE-2026-19903), and unrestricted uploads in the Simple Doctors Appointment System (CVE-2026-19839).
The batch of vulnerabilities spans multiple SourceCodester products, including Simple Online Food Ordering System, Onlne Examination & Learning Management System, Class and Exam Timetabling System, Pet Grooming Management Software, Best Employee Management System, Stock Management System, Online Book Store System, Online Clothing Store, Simple Doctors Appointment System, Simple Client Management System, Air Cargo Management System, and Simple Student Information System. The affected versions are not explicitly detailed for all CVEs, but the descriptions suggest that these are likely older versions of the software, as is common with vulnerabilities found in such systems.
The widespread disclosure of these vulnerabilities, with many exploits already made public, underscores the urgent need for users of SourceCodester products to review and update their systems. The prevalence of SQL injection flaws, in particular, poses a significant risk to data integrity and confidentiality. Users should consult any available advisories from SourceCodester or security researchers for specific patching instructions and mitigation strategies. The disclosure window of August 13-19, 2026, indicates a coordinated or closely timed release of security information, highlighting a critical period for system administrators to address these security weaknesses.
Key Findings:
- A batch of 18 vulnerabilities was disclosed for SourceCodester products between August 13-19, 2026.
- Multiple SQL injection vulnerabilities (CVE-2026-76050, CVE-2026-76049, CVE-2026-76048, CVE-2026-75080, CVE-2026-75079, CVE-2026-75014, CVE-2026-19925, CVE-2026-19899, CVE-2026-19825, CVE-2026-19787, CVE-2026-19710) were found across several applications.
- High-severity SQL injection flaws (CVSSv3 7.3) were prevalent, with exploits publicly disclosed.
- Other vulnerability types include CSRF, XSS, directory listing, file accessibility, and unrestricted uploads.
- The vulnerabilities affect a range of SourceCodester systems, including ordering, timetabling, and management software.
CVE IDs: CVE-2026-76050, CVE-2026-76049, CVE-2026-76048, CVE-2026-75151, CVE-2026-75080, CVE-2026-75079, CVE-2026-75078, CVE-2026-75077, CVE-2026-75014, CVE-2026-19987, CVE-2026-19925, CVE-2026-19904, CVE-2026-19903, CVE-2026-19899, CVE-2026-19839, CVE-2026-19825, CVE-2026-19787, CVE-2026-19710
Image Prompt: A stylized representation of database tables with SQL code fragments being injected and corrupting the data. The overall aesthetic should be digital and abstract, focusing on the flow of information and its disruption.