VYPR

Vendor CVEs

Sourcecodester

All CVEs

2,501 total · sorted by risk
  • CVE-2023-46004HigOct 18, 2023
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Best Courier Management System 1.0 is vulnerable to Arbitrary file upload in the update_user function.

  • CVE-2023-44047HigSep 27, 2023
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Toll Tax Management System v1 is vulnerable to SQL Injection.

  • CVE-2023-4184HigAug 6, 2023
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file sell_return.php. The manipulation of the argument pid leads to sql injection. The attack may be initiated remotely. The…

  • CVE-2023-4182HigAug 6, 2023
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file edit_sell.php. The manipulation of the argument up_pid leads to sql injection. It is possible to initiate the attack remotely.…

  • CVE-2023-33569HigJun 6, 2023
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via ip/eval/ajax.php?action=update_user.

  • CVE-2023-33439HigMay 26, 2023
    risk 0.47cvss 7.2epss 0.03

    Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_task.php?id=.

  • CVE-2023-31845HigMay 15, 2023
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_class.php?id=.

  • CVE-2023-31844HigMay 15, 2023
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_subject.php?id=.

  • CVE-2023-31843HigMay 15, 2023
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/view_faculty.php?id=.

  • CVE-2023-31842HigMay 15, 2023
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/index.php?page=edit_faculty&id=.

  • CVE-2023-1737HigMar 30, 2023
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. This affects an unknown part of the file login.php. The manipulation of the argument U_USERNAME leads to sql injection. It is possible to initiate the attack…

  • CVE-2023-1734HigMar 30, 2023
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. Affected is an unknown function of the file admin/products/controller.php?action=add. The manipulation of the argument image leads to unrestricted upload. It is…

  • CVE-2023-1432HigMar 16, 2023
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Online Food Ordering System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /fos/admin/ajax.php?action=save_settings of the component POST Request Handler. The manipulation leads to…

  • CVE-2023-1357HigMar 12, 2023
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Simple Bakery Shop Management System 1.0. Affected by this issue is some unknown functionality of the component Admin Login. The manipulation of the argument username/password with the input…

  • CVE-2023-0774HigFeb 10, 2023
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in SourceCodester Medical Certificate Generator App 1.0 and classified as critical. This vulnerability affects unknown code of the file action.php. The manipulation of the argument lastname leads to sql injection. The attack can be initiated…

  • CVE-2022-44137HigDec 30, 2022
    risk 0.47cvss 7.2epss 0.01

    SourceCodester Sanitization Management System 1.0 is vulnerable to SQL Injection.

  • CVE-2022-4739HigDec 25, 2022
    risk 0.47cvss 7.3epss 0.00

    A vulnerability classified as critical was found in SourceCodester School Dormitory Management System 1.0. Affected by this vulnerability is an unknown functionality of the component Admin Login. The manipulation leads to sql injection. The attack can be launched remotely. The…

  • CVE-2022-4737HigDec 25, 2022
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated…

  • CVE-2022-43146HigNov 14, 2022
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in the image upload function of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2022-3674HigOct 26, 2022
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in SourceCodester Sanitization Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to missing authentication. The attack can be launched remotely. The identifier…

  • CVE-2022-42201HigOct 20, 2022
    risk 0.47cvss 7.2epss 0.01

    Simple Exam Reviewer Management System v1.0 is vulnerable to Insecure file upload.

  • CVE-2022-40026HigSep 21, 2022
    risk 0.47cvss 7.2epss 0.01

    SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at board.php.

  • CVE-2022-2702HigAug 8, 2022
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Company Website CMS and classified as critical. Affected by this issue is some unknown functionality of the file site-settings.php of the component Cookie Handler. The manipulation leads to improper access controls. The attack may be…

  • CVE-2022-2674HigAug 5, 2022
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Best Fee Management System. It has been rated as critical. Affected by this issue is the function login of the file admin_class.php. The manipulation of the argument username leads to sql injection. The attack may be launched remotely.…

  • CVE-2022-30379HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=user/manage_user&id=.

  • CVE-2022-30378HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=posts/view_post&id=.

  • CVE-2022-30376HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/members/view_member.php?id=.

  • CVE-2021-46079HigJan 6, 2022
    risk 0.47cvss 7.2epss 0.03

    An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can upload malicious files leading to Html Injection.

  • CVE-2021-46075HigJan 6, 2022
    risk 0.47cvss 7.2epss 0.03

    A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users can access the admin resources and perform CRUD Operations.

  • CVE-2021-41675HigOct 29, 2021
    risk 0.47cvss 7.2epss 0.03

    A Remote Code Execution (RCE) vulnerabilty exists in Sourcecodester E-Negosyo System 1.0 in /admin/produts/controller.php via the doInsert function, which validates images with getImageSizei. .

  • CVE-2020-28072HigDec 15, 2020
    risk 0.47cvss 7.2epss 0.03

    A Remote Code Execution vulnerability exists in DourceCodester Alumni Management System 1.0. An authenticated attacker can upload arbitrary file in the gallery.php page and executing it on the server reaching the RCE.

  • CVE-2018-25207HigMar 26, 2026
    risk 0.46cvss 7.1epss 0.00

    Online Quiz Maker 1.0 contains SQL injection vulnerabilities in the catid and usern parameters that allow authenticated attackers to execute arbitrary SQL commands. Attackers can submit malicious POST requests to quiz-system.php or add-category.php with crafted SQL payloads in…

  • CVE-2025-63711HigNov 10, 2025
    risk 0.46cvss 7.1epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability in the SourceCodester Client Database Management System 1.0 allows an attacker to cause an authenticated administrative user to perform user deletion actions without their consent. The application's user deletion endpoint (e.g.,…

  • CVE-2024-34231HigMay 14, 2024
    risk 0.46cvss 7.1epss 0.00

    A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the System Short Name parameter.

  • CVE-2020-23830HigSep 2, 2020
    risk 0.46cvss 7.1epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability in changeUsername.php in SourceCodester Stock Management System v1.0 allows remote attackers to deny future logins by changing an authenticated victim's username when they visit a third-party site.

  • CVE-2020-23835MedSep 1, 2020
    risk 0.45cvss 6.4epss 0.02

    A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Management System v1.0 allows remote attackers to harvest keys pressed by an unauthenticated victim who clicks on a malicious URL and begins typing.

  • CVE-2023-2246MedApr 23, 2023
    risk 0.44cvss 6.3epss 0.04

    A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file admin/ajax.php?action=save_settings. The manipulation of the argument img leads to unrestricted upload. The attack…

  • CVE-2023-1826MedApr 4, 2023
    risk 0.44cvss 6.3epss 0.04

    A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. This affects an unknown part of the file php-ocls\admin\system_info\index.php. The manipulation of the argument img leads to unrestricted upload. It is possible…

  • CVE-2023-0962MedFeb 22, 2023
    risk 0.44cvss 6.3epss 0.02

    A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been declared as critical. This vulnerability affects unknown code of the file Master.php of the component GET Request Handler. The manipulation of the argument id leads to sql injection. The attack can…

  • CVE-2023-0961MedFeb 22, 2023
    risk 0.44cvss 6.3epss 0.02

    A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been classified as critical. This affects an unknown part of the file view_music_details.php of the component GET Request Handler. The manipulation of the argument id leads to sql injection. It is…

  • CVE-2023-0938MedFeb 21, 2023
    risk 0.44cvss 6.3epss 0.02

    A vulnerability classified as critical has been found in SourceCodester Music Gallery Site 1.0. This affects an unknown part of the file music_list.php of the component GET Request Handler. The manipulation of the argument cid leads to sql injection. It is possible to initiate…

  • CVE-2023-0916MedFeb 19, 2023
    risk 0.44cvss 6.3epss 0.03

    A vulnerability classified as critical was found in SourceCodester Auto Dealer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /adms/classes/Users.php. The manipulation leads to improper access controls. The attack can be launched…

  • CVE-2023-0915MedFeb 19, 2023
    risk 0.44cvss 6.3epss 0.02

    A vulnerability classified as critical has been found in SourceCodester Auto Dealer Management System 1.0. Affected is an unknown function of the file /adms/admin/?page=user/manage_user. The manipulation of the argument id leads to sql injection. It is possible to launch the…

  • CVE-2023-0904MedFeb 18, 2023
    risk 0.44cvss 6.3epss 0.02

    A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file task-details.php. The manipulation of the argument task_id leads to sql injection. The attack may be initiated…

  • CVE-2022-2297MedJul 12, 2022
    risk 0.44cvss 6.3epss 0.03

    A vulnerability, which was classified as critical, was found in SourceCodester Clinics Patient Management System 2.0. Affected is an unknown function of the file /pms/update_user.php?user_id=1. The manipulation of the argument profile_picture with the input <?php phpinfo();?>…

  • CVE-2024-0265MedJan 7, 2024
    risk 0.43cvss 6.3epss 0.21

    A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php of the component GET Parameter Handler. The manipulation of the argument page leads to file inclusion. The…

  • CVE-2026-9603MedMay 26, 2026
    risk 0.42cvss 6.5epss 0.00

    A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The manipulation of the argument ID leads to missing authorization. Remote exploitation of the attack is possible.…

  • CVE-2021-36438MedApr 27, 2026
    risk 0.42cvss 6.5epss 0.00

    SQL Injection vulnerability exists in Sourcecodester Online Job Portal phppdo 1.0 ivia the category parameter in /jobportal/index.php.

  • CVE-2026-5330MedApr 2, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=delete_user of the component User Delete Handler. Performing a manipulation of the argument ID results in…

  • CVE-2026-30523MedApr 1, 2026
    risk 0.42cvss 6.5epss 0.00

    A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input validation. The application allows administrators to define "Loan Plans" which determine the duration of a loan (in months). However, the backend fails to validate…

Page 14 of 51