VYPR

Vendor CVEs

Remyandrade

All CVEs

77 total · sorted by risk
  • CVE-2024-24496CriFeb 8, 2024
    risk 0.68cvss 9.8epss 0.20

    An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components.

  • CVE-2024-24495CriFeb 8, 2024
    risk 0.67cvss 9.8epss 0.01

    SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via crafted GET request.

  • CVE-2025-70457CriJan 23, 2026
    risk 0.64cvss 9.8epss 0.01

    A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension…

  • CVE-2024-25302CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter.

  • CVE-2024-24141CriJan 29, 2024
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester School Task Manager App 1.0 allows SQL Injection via the 'task' parameter.

  • CVE-2025-1160HigFeb 10, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argument username/password leads to use of default credentials. The…

  • CVE-2024-1197HigFeb 2, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Testimonial Page Manager 1.0. This issue affects some unknown processing of the file delete-testimonial.php of the component HTTP GET Request Handler. The manipulation of the argument testimony…

  • CVE-2024-24140HigJan 29, 2024
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'

  • CVE-2024-24139HigJan 29, 2024
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.

  • CVE-2024-24494MedFeb 8, 2024
    risk 0.45cvss 6.1epss 0.26

    Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, read_book, vitamins, laundry, alcohol and meat parameters in the add-tracker.php and update-tracker.php components.

  • CVE-2025-63892MedNov 18, 2025
    risk 0.44cvss 6.8epss 0.00

    A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function create_classroom of the file /classroom.php of the component My Classrooms Management Page. This manipulation of the argument name/description causes stored cross site…

  • CVE-2026-3695MedMar 8, 2026
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been found in SourceCodester Modern Image Gallery App 1.0. Impacted is an unknown function of the file /delete.php. Such manipulation of the argument filename leads to path traversal. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2023-47014MedNov 22, 2023
    risk 0.42cvss 6.5epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability in Sourcecodester Sticky Notes App Using PHP with Source Code v.1.0 allows a local attacker to obtain sensitive information via a crafted payload to add-note.php.

  • CVE-2026-3163MedFeb 25, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in SourceCodester Website Link Extractor 1.0. This vulnerability affects the function file_get_contents of the component URL Handler. The manipulation leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit…

  • CVE-2025-1166MedFeb 11, 2025
    risk 0.41cvss 6.3epss 0.01

    A vulnerability has been found in SourceCodester Food Menu Manager 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file endpoint/update.php. The manipulation leads to unrestricted upload. The attack can be launched remotely. The…

  • CVE-2024-8380MedSep 3, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been rated as critical. This issue affects some unknown processing of the file /endpoint/delete-account.php of the component Delete Contact Handler. The manipulation of the argument…

  • CVE-2024-7748MedAug 13, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Accounts Manager App 1.0. This issue affects some unknown processing of the file /endpoint/delete-account.php. The manipulation of the argument account leads to sql injection. The attack may be…

  • CVE-2024-5134MedMay 20, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Electricity Consumption Monitoring Tool 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-bill.php. The manipulation of the argument bill leads to sql injection. The attack can…

  • CVE-2024-2934MedMar 27, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in SourceCodester Todo List in Kanban Board 1.0. Affected by this vulnerability is an unknown functionality of the file /endpoint/delete-todo.php. The manipulation of the argument list leads to sql injection. The attack can be…

  • CVE-2024-2604MedMar 18, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester File Manager App 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/update-file.php. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated…

  • CVE-2024-2393MedMar 12, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester CRUD without Page Reload 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file add_user.php. The manipulation of the argument city leads to sql injection. The attack can be…

  • CVE-2024-2069MedMar 1, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in SourceCodester FAQ Management System 1.0. Affected is an unknown function of the file /endpoint/delete-faq.php. The manipulation of the argument faq leads to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2024-2067MedMar 1, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in SourceCodester Computer Inventory System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-computer.php. The manipulation of the argument computer leads to sql injection. The attack can be…

  • CVE-2023-6464MedDec 2, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester User Registration and Login System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /endpoint/add-user.php. The manipulation of the argument user leads to sql injection. The attack may be…

  • CVE-2023-5792MedOct 26, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability has been found in SourceCodester Sticky Notes App 1.0 and classified as critical. This vulnerability affects unknown code of the file endpoint/delete-note.php. The manipulation of the argument note leads to sql injection. The attack can be initiated remotely. The…

  • CVE-2023-5790MedOct 26, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in SourceCodester File Manager App 1.0. Affected by this vulnerability is an unknown functionality of the file endpoint/add-file.php. The manipulation of the argument uploadedFileName leads to unrestricted upload. The attack can…

  • CVE-2025-63708MedNov 17, 2025
    risk 0.40cvss 6.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability exists in SourceCodester AI Font Matcher (nid=18425, 2025-10-10) that allows remote attackers to execute arbitrary JavaScript in victims' browsers. The vulnerability occurs in the webfonts API handling mechanism where font family names…

  • CVE-2025-63639MedNov 7, 2025
    risk 0.40cvss 6.1epss 0.00

    The chat feature in the application Sourcecodester FAQ Bot with AI Assistant v1.0 is vulnerable to Cross-Site Scripting (XSS) due to improper handling of user-supplied input. An attacker can inject malicious HTML or JavaScript into chat messages, which executes in the browser of…

  • CVE-2025-63638MedNov 7, 2025
    risk 0.40cvss 6.1epss 0.00

    Sourcecodester AI-Powered To-Do List App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Task Title" and "Description (Optional)" fields when creating a Task, allowing an attacker to inject arbitrary potentially malicious HTML/JavaScript code that executes in the…

  • CVE-2025-63714MedNov 7, 2025
    risk 0.40cvss 6.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in SourceCodester User Account Generator 1.0 allows remote attackers to execute arbitrary JavaScript code in the context of the user's browser session via crafted input in the Username Prefix field. The vulnerability exists due to…

  • CVE-2025-63713MedNov 7, 2025
    risk 0.40cvss 6.1epss 0.00

    Cross-Site Scripting (XSS) vulnerability in SourceCodester "MatchMaster" 1.0 allows remote attackers to inject arbitrary web script or HTML via crafted input in the custom test creation feature. The vulnerability exists because the application fails to properly sanitize…

  • CVE-2025-26258MedSep 26, 2025
    risk 0.40cvss 6.1epss 0.00

    Sourcecodester Employee Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via 'Add Designation.'

  • CVE-2025-57425MedAug 26, 2025
    risk 0.40cvss 6.1epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability in SourceCodester FAQ Management System 1.0 allows an authenticated attacker to inject malicious JavaScript into the 'question' and 'answer' fields via the update-faq.php endpoint.

  • CVE-2025-29719MedApr 2, 2025
    risk 0.40cvss 6.1epss 0.00

    SourceCodester (rems) Employee Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add_employee.php via the First Name and Address text fields.

  • CVE-2024-28277MedMay 14, 2024
    risk 0.40cvss 6.1epss 0.00

    In Sourcecodester School Task Manager v1.0, a vulnerability was identified within the subject_name= parameter, enabling Stored Cross-Site Scripting (XSS) attacks. This vulnerability allows attackers to manipulate the subject's name, potentially leading to the execution of…

  • CVE-2024-24945MedFeb 1, 2024
    risk 0.40cvss 6.1epss 0.00

    A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Share Your Moments parameter at /travel-journal/write-journal.php.

  • CVE-2024-24041MedFeb 1, 2024
    risk 0.40cvss 6.1epss 0.00

    A stored cross-site scripting (XSS) vulnerability in Travel Journal Using PHP and MySQL with Source Code v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the location parameter at /travel-journal/write-journal.php.

  • CVE-2024-24136MedJan 29, 2024
    risk 0.40cvss 6.1epss 0.01

    The 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cross-Site Scripting (XSS) attacks.

  • CVE-2024-24135MedJan 29, 2024
    risk 0.40cvss 6.1epss 0.01

    Product Name and Product Code in the 'Add Product' section of Sourcecodester Product Inventory with Export to Excel 1.0 are vulnerable to XSS attacks.

  • CVE-2025-70458MedJan 23, 2026
    risk 0.35cvss 5.4epss 0.00

    A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sourcecodester Domain Availability Checker v1.0. The vulnerability occurs because the application improperly handles user-supplied data in the createResultElement…

  • CVE-2025-64070MedDec 2, 2025
    risk 0.35cvss 5.4epss 0.00

    Sourcecodester Student Grades Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the Add New Subject Description field.

  • CVE-2025-57117MedSep 15, 2025
    risk 0.35cvss 5.4epss 0.00

    A Clickjacking vulnerability exists in Rems' Employee Management System 1.0. This flaw allows remote attackers to execute arbitrary JavaScript on the department.php page by injecting a malicious payload into the Department Name field under Add Department.

  • CVE-2025-14530MedDec 11, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability has been found in SourceCodester Real Estate Property Listing App 1.0. The impacted element is an unknown function of the file /admin/property.php. Such manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely.…

  • CVE-2024-8559MedSep 7, 2024
    risk 0.31cvss 4.7epss 0.00

    A vulnerability, which was classified as critical, has been found in SourceCodester Online Food Menu 1.0. This issue affects some unknown processing of the file /endpoint/delete-menu.php. The manipulation of the argument menu leads to sql injection. The attack may be initiated…

  • CVE-2024-24050MedMar 20, 2024
    risk 0.31cvss 4.7epss 0.00

    Cross Site Scripting (XSS) vulnerability in Sourcecodester Workout Journal App 1.0 allows attackers to run arbitrary code via parameters firstname and lastname in /add-user.php.

  • CVE-2024-24134MedJan 29, 2024
    risk 0.31cvss 4.8epss 0.01

    Sourcecodester Online Food Menu 1.0 is vulnerable to Cross Site Scripting (XSS) via the 'Menu Name' and 'Description' fields in the Update Menu section.

  • CVE-2026-3302MedFeb 27, 2026
    risk 0.28cvss 4.3epss 0.00

    A weakness has been identified in SourceCodester Doctor Appointment System 1.0. Affected by this issue is some unknown functionality of the file /register.php of the component Sign Up Page. Executing a manipulation of the argument Email can lead to cross site scripting. The…

  • CVE-2026-3070MedFeb 24, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was detected in SourceCodester Modern Image Gallery App 1.0. Affected by this vulnerability is an unknown functionality of the file upload.php. The manipulation of the argument filename results in cross site scripting. The attack may be launched remotely. The…

  • CVE-2024-1196MedFeb 2, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic was found in SourceCodester Testimonial Page Manager 1.0. This vulnerability affects unknown code of the file add-testimonial.php of the component HTTP POST Request Handler. The manipulation of the argument name/description/testimony…

  • CVE-2023-6767MedDec 13, 2023
    risk 0.28cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, was found in SourceCodester Wedding Guest e-Book 1.0. This affects an unknown part of the file /endpoint/add-guest.php. The manipulation of the argument name leads to cross site scripting. It is possible to initiate the…

Page 1 of 2