Vendor CVEs
Sourcecodester
All CVEs
2,498 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-33584 | Cri | 0.68 | 9.8 | 0.14 | Jun 21, 2023 | Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the username and password fields… | ||
| CVE-2023-34581 | Cri | 0.67 | 9.8 | 0.03 | Jun 12, 2023 | Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2 | ||
| CVE-2021-42580 | Cri | 0.67 | 9.8 | 0.10 | Nov 15, 2021 | Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) file , we can craft these two vunlerablities to get unauthenticated remote command execution. | ||
| CVE-2021-43140 | Cri | 0.67 | 9.8 | 0.05 | Nov 3, 2021 | SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login. | ||
| CVE-2021-42669 | Cri | 0.66 | 9.8 | 0.23 | Nov 5, 2021 | A file upload vulnerability exists in Sourcecodester Engineers Online Portal in PHP via dashboard_teacher.php, which allows changing the avatar through teacher_avatar.php. Once an avatar gets uploaded it is getting uploaded to the /admin/uploads/ directory, and is accessible by… | ||
| CVE-2020-28070 | Cri | 0.66 | 9.8 | 0.23 | Dec 23, 2020 | SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GET input in view_event.php via the 'id' parameter. | ||
| CVE-2022-28531 | Cri | 0.65 | 9.8 | 0.15 | May 20, 2022 | Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtusername (aka Username) field. | ||
| CVE-2021-42667 | Cri | 0.65 | 9.8 | 0.16 | Nov 5, 2021 | A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. An attacker can leverage this vulnerability in order to manipulate the sql query performed. As a result he can extract sensitive data from the web… | ||
| CVE-2026-37345 | Cri | 0.64 | 9.8 | 0.00 | Apr 16, 2026 | SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php. | ||
| CVE-2026-37340 | Cri | 0.64 | 9.8 | 0.00 | Apr 16, 2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php. | ||
| CVE-2026-37339 | Cri | 0.64 | 9.8 | 0.00 | Apr 16, 2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php. | ||
| CVE-2026-36236 | Cri | 0.64 | 9.8 | 0.00 | Apr 10, 2026 | SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter. | ||
| CVE-2026-30533 | Cri | 0.64 | 9.8 | 0.00 | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter. | ||
| CVE-2026-30532 | Cri | 0.64 | 9.8 | 0.00 | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter. | ||
| CVE-2026-30530 | Cri | 0.64 | 9.8 | 0.00 | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an attacker to inject… | ||
| CVE-2026-26707 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php. | ||
| CVE-2026-26706 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_receipt.php. | ||
| CVE-2026-26705 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_product.php. | ||
| CVE-2026-26704 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_category.php. | ||
| CVE-2026-26708 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_user.php. | ||
| CVE-2026-26700 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_employee.php. | ||
| CVE-2026-26701 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_tecnical_user.php. | ||
| CVE-2026-26703 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2026 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/advance_search.php. | ||
| CVE-2026-26702 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2026 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/myitem_reuse.php. | ||
| CVE-2025-70457 | Cri | 0.64 | 9.8 | 0.01 | Jan 23, 2026 | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension… | ||
| CVE-2025-66802 | Cri | 0.64 | 9.8 | 0.01 | Jan 12, 2026 | Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receives a reverse shell (php) into imagem of the user enabling RCE. | ||
| CVE-2025-64081 | Cri | 0.64 | 9.8 | 0.00 | Dec 8, 2025 | SQL injection vulnerability in /php/api_patient_schedule.php in SourceCodester Patients Waiting Area Queue Management System v1 allows attackers to execute arbitrary SQL commands via the appointmentID parameter. | ||
| CVE-2021-4462 | Cri | 0.64 | 9.8 | 0.03 | Nov 10, 2025 | Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; uploaded files can be executed because the application does not perform proper… | ||
| CVE-2025-46192 | Cri | 0.64 | 9.8 | 0.00 | May 9, 2025 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the order_id POST parameter. | ||
| CVE-2025-46191 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2025 | Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to the absence of proper file extension checks, MIME type validation, and… | ||
| CVE-2025-46190 | Cri | 0.64 | 9.8 | 0.00 | May 9, 2025 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the order_id POST parameter. | ||
| CVE-2025-46193 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2025 | SourceCodester Client Database Management System 1.0 is vulnerable to Remote code execution via Arbitrary file upload in user_proposal_update_order.php. | ||
| CVE-2025-46189 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2025 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id POST parameter. | ||
| CVE-2025-46188 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2025 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php. | ||
| CVE-2025-44192 | Cri | 0.64 | 9.8 | 0.00 | Apr 30, 2025 | SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_clearance. | ||
| CVE-2025-29709 | Cri | 0.64 | 9.8 | 0.01 | Apr 16, 2025 | SourceCodester Company Website CMS 1.0 has a File upload vulnerability via the "Create portfolio" file /dashboard/portfolio. | ||
| CVE-2025-29708 | Cri | 0.64 | 9.8 | 0.01 | Apr 16, 2025 | SourceCodester Company Website CMS 1.0 contains a file upload vulnerability via the "Create Services" file /dashboard/Services. | ||
| CVE-2024-40073 | Cri | 0.64 | 9.8 | 0.00 | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4. | ||
| CVE-2024-40072 | Cri | 0.64 | 9.8 | 0.00 | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1. | ||
| CVE-2024-40071 | Cri | 0.64 | 9.8 | 0.01 | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2025-28087 | Cri | 0.64 | 9.8 | 0.00 | Mar 28, 2025 | Sourcecodester Online Exam System 1.0 is vulnerable to SQL Injection via dash.php. | ||
| CVE-2020-36084 | Cri | 0.64 | 9.8 | 0.01 | Feb 5, 2025 | SQL Injection vulnerability in SourceCodester Responsive E-Learning System 1.0 allows remote attackers to inject sql query in /elearning/delete_teacher_students.php?id= parameter via id field. | ||
| CVE-2024-52675 | Cri | 0.64 | 9.8 | 0.01 | Nov 19, 2024 | SourceCodester Sentiment Based Movie Rating System 1.0 is vulnerable to SQL Injection in /msrps/movies.php. | ||
| CVE-2024-50766 | Cri | 0.64 | 9.8 | 0.01 | Nov 7, 2024 | SourceCodester Survey Application System 1.0 is vulnerable to SQL Injection in takeSurvey.php via the id parameter. | ||
| CVE-2024-46293 | Cri | 0.64 | 9.8 | 0.00 | Sep 30, 2024 | Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session token. The application does… | ||
| CVE-2024-40472 | Cri | 0.64 | 9.8 | 0.01 | Aug 12, 2024 | Sourcecodester Daily Calories Monitoring Tool v1.0 is vulnerable to SQL Injection via "delete-calorie.php." | ||
| CVE-2024-34480 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2024 | SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection. | ||
| CVE-2024-34479 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2024 | SourceCodester Computer Laboratory Management System 1.0 allows classes/Master.php id SQL Injection. | ||
| CVE-2024-40392 | Cri | 0.64 | 9.8 | 0.01 | Jul 16, 2024 | SourceCodester Pharmacy/Medical Store Point of Sale System Using PHP/MySQL and Bootstrap Framework with Source Code 1.0 was discovered to contain a SQL injection vulnerability via the name parameter under addnew.php. | ||
| CVE-2024-40110 | Cri | 0.64 | 9.8 | 0.02 | Jul 12, 2024 | Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability via the productimage parameter at /farm/product.php. |
- risk 0.68cvss 9.8epss 0.14
Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the username and password fields…
- risk 0.67cvss 9.8epss 0.03
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2
- risk 0.67cvss 9.8epss 0.10
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) file , we can craft these two vunlerablities to get unauthenticated remote command execution.
- risk 0.67cvss 9.8epss 0.05
SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.
- risk 0.66cvss 9.8epss 0.23
A file upload vulnerability exists in Sourcecodester Engineers Online Portal in PHP via dashboard_teacher.php, which allows changing the avatar through teacher_avatar.php. Once an avatar gets uploaded it is getting uploaded to the /admin/uploads/ directory, and is accessible by…
- risk 0.66cvss 9.8epss 0.23
SourceCodester Alumni Management System 1.0 is affected by SQL injection causing arbitrary remote code execution from GET input in view_event.php via the 'id' parameter.
- risk 0.65cvss 9.8epss 0.15
Sourcecodester Covid-19 Directory on Vaccination System1.0 is vulnerable to SQL Injection via the admin/login.php txtusername (aka Username) field.
- risk 0.65cvss 9.8epss 0.16
A SQL Injection vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP in event-management/views. An attacker can leverage this vulnerability in order to manipulate the sql query performed. As a result he can extract sensitive data from the web…
- risk 0.64cvss 9.8epss 0.00
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/manage_park.php.
- risk 0.64cvss 9.8epss 0.00
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php.
- risk 0.64cvss 9.8epss 0.00
SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php.
- risk 0.64cvss 9.8epss 0.00
SourceCodester Engineers Online Portal v1.0 is vulnerable to SQL Injection in update_password.php via the new_password parameter.
- risk 0.64cvss 9.8epss 0.00
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter.
- risk 0.64cvss 9.8epss 0.00
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter.
- risk 0.64cvss 9.8epss 0.00
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an attacker to inject…
- risk 0.64cvss 9.8epss 0.00
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php.
- risk 0.64cvss 9.8epss 0.00
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_receipt.php.
- risk 0.64cvss 9.8epss 0.00
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_product.php.
- risk 0.64cvss 9.8epss 0.00
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_category.php.
- risk 0.64cvss 9.8epss 0.00
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_user.php.
- risk 0.64cvss 9.8epss 0.00
sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_employee.php.
- risk 0.64cvss 9.8epss 0.00
sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_tecnical_user.php.
- risk 0.64cvss 9.8epss 0.01
sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/advance_search.php.
- risk 0.64cvss 9.8epss 0.01
sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/myitem_reuse.php.
- risk 0.64cvss 9.8epss 0.01
A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension…
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receives a reverse shell (php) into imagem of the user enabling RCE.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability in /php/api_patient_schedule.php in SourceCodester Patients Waiting Area Queue Management System v1 allows attackers to execute arbitrary SQL commands via the appointmentID parameter.
- risk 0.64cvss 9.8epss 0.03
Employee Records System version 1.0 contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload arbitrary files via the uploadID.php endpoint; uploaded files can be executed because the application does not perform proper…
- risk 0.64cvss 9.8epss 0.00
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the order_id POST parameter.
- risk 0.64cvss 9.8epss 0.01
Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to the absence of proper file extension checks, MIME type validation, and…
- risk 0.64cvss 9.8epss 0.00
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the order_id POST parameter.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Client Database Management System 1.0 is vulnerable to Remote code execution via Arbitrary file upload in user_proposal_update_order.php.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id POST parameter.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.
- risk 0.64cvss 9.8epss 0.00
SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_clearance.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Company Website CMS 1.0 has a File upload vulnerability via the "Create portfolio" file /dashboard/portfolio.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Company Website CMS 1.0 contains a file upload vulnerability via the "Create Services" file /dashboard/Services.
- risk 0.64cvss 9.8epss 0.00
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4.
- risk 0.64cvss 9.8epss 0.00
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.00
Sourcecodester Online Exam System 1.0 is vulnerable to SQL Injection via dash.php.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in SourceCodester Responsive E-Learning System 1.0 allows remote attackers to inject sql query in /elearning/delete_teacher_students.php?id= parameter via id field.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Sentiment Based Movie Rating System 1.0 is vulnerable to SQL Injection in /msrps/movies.php.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Survey Application System 1.0 is vulnerable to SQL Injection in takeSurvey.php via the id parameter.
- risk 0.64cvss 9.8epss 0.00
Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session token. The application does…
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Daily Calories Monitoring Tool v1.0 is vulnerable to SQL Injection via "delete-calorie.php."
- risk 0.64cvss 9.8epss 0.01
SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Computer Laboratory Management System 1.0 allows classes/Master.php id SQL Injection.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Pharmacy/Medical Store Point of Sale System Using PHP/MySQL and Bootstrap Framework with Source Code 1.0 was discovered to contain a SQL injection vulnerability via the name parameter under addnew.php.
- risk 0.64cvss 9.8epss 0.02
Sourcecodester Poultry Farm Management System v1.0 contains an Unauthenticated Remote Code Execution (RCE) vulnerability via the productimage parameter at /farm/product.php.
Page 1 of 50