VYPR

Vendor CVEs

Sourcecodester

All CVEs

2,501 total · sorted by risk
  • CVE-2021-27332MedJul 22, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the class_name parameter to update_class.php.

  • CVE-2021-26224MedJul 22, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in SourceCodester Fantastic-Blog-CMS V 1.0 allows remote attackers to inject arbitrary web script or HTML via the search field to search.php.

  • CVE-2021-25197MedJul 22, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in SourceCodester Content Management System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter to content_management_system\admin\new_content.php

  • CVE-2021-26230MedJul 22, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the user information to save_user.php.

  • CVE-2021-26227MedJul 22, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in SourceCodester CASAP Automated Enrollment System v 1.0 allows remote attackers to inject arbitrary web script or HTML via the student information parameters to edit_stud.php.

  • CVE-2020-28129MedNov 17, 2020
    risk 0.40cvss 6.1epss 0.01

    Stored Cross-site scripting (XSS) vulnerability in SourceCodester Gym Management System 1.0 allows users to inject and store arbitrary JavaScript code in index.php?page=packages via vulnerable fields 'Package Name' and 'Description'.

  • CVE-2020-28139MedNov 17, 2020
    risk 0.40cvss 6.1epss 0.01

    SourceCodester Online Clothing Store 1.0 is affected by a cross-site scripting (XSS) vulnerability via a Offer Detail field in offer.php.

  • CVE-2020-25272MedOct 8, 2020
    risk 0.40cvss 6.1epss 0.01

    In SourceCodester Online Bus Booking System 1.0, there is XSS through the name parameter in book_now.php.

  • CVE-2020-24198MedSep 9, 2020
    risk 0.40cvss 6.1epss 0.01

    A persistent cross-site scripting vulnerability in Sourcecodester Stock Management System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'Brand Name.'

  • CVE-2020-24194MedSep 9, 2020
    risk 0.40cvss 6.1epss 0.01

    A Cross-site scripting (XSS) vulnerability in 'user-profile.php' in SourceCodester Daily Tracker System v1.0 allows remote attackers to inject arbitrary web script or HTML via the 'fullname' parameter.

  • CVE-2019-18416MedOct 24, 2019
    risk 0.40cvss 6.1epss 0.01

    Sourcecodester Restaurant Management System 1.0 allows XSS via the Last Name field of a member.

  • CVE-2019-18415MedOct 24, 2019
    risk 0.40cvss 6.1epss 0.01

    Sourcecodester Restaurant Management System 1.0 allows XSS via the "send a message" screen.

  • CVE-2024-40068MedApr 16, 2025
    risk 0.38cvss 5.9epss 0.00

    Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=templates/manage_template&id=1.

  • CVE-2024-34222MedMay 14, 2024
    risk 0.38cvss 5.9epss 0.00

    Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the searccountry parameter.

  • CVE-2021-40577MedNov 8, 2021
    risk 0.38cvss 5.4epss 0.02

    A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP and PayPal Free Source Code 1.0 in the Add-Users page via the Name parameter.

  • CVE-2021-25791MedJul 23, 2021
    risk 0.38cvss 5.4epss 0.03

    Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields.

  • CVE-2024-5098MedMay 19, 2024
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been found in SourceCodester Simple Inventory System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file login.php. The manipulation of the argument username leads to sql injection. The exploit has been…

  • CVE-2024-3466MedApr 8, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Laundry Management System 1.0. It has been declared as critical. Affected by this vulnerability is the function laporan_filter of the file /application/controller/Pengeluaran.php. The manipulation of the argument dari/sampai leads to…

  • CVE-2023-6898MedDec 17, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Best Courier Management System 1.0. Affected is an unknown function of the file manage_user.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and…

  • CVE-2023-6771MedDec 13, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Simple Student Attendance System 1.0. This issue affects the function save_attendance of the file actions.class.php. The manipulation of the argument sid leads to sql injection. The exploit has…

  • CVE-2023-6765MedDec 13, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. This issue affects the function prepare of the file email_setup.php. The manipulation of the argument name leads to sql injection. The exploit has been…

  • CVE-2023-6658MedDec 10, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability classified as critical was found in SourceCodester Simple Student Attendance System 1.0. This vulnerability affects unknown code of the file ajax-api.php?action=save_attendance. The manipulation of the argument class_id leads to sql injection. The exploit has…

  • CVE-2023-6657MedDec 10, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Simple Student Attendance System 1.0. This affects an unknown part of the file /modals/student_form.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the…

  • CVE-2023-6619MedDec 8, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /modals/class_form.php. The manipulation of the argument id leads to sql injection. The exploit has…

  • CVE-2023-6618MedDec 8, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument page leads to file inclusion. The exploit has…

  • CVE-2023-6617MedDec 8, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been classified as critical. Affected is an unknown function of the file attendance.php. The manipulation of the argument class_id leads to sql injection. The exploit has been disclosed to…

  • CVE-2023-5272MedSep 29, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Best Courier Management System 1.0. This affects an unknown part of the file edit_parcel.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The exploit…

  • CVE-2023-5271MedSep 29, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file edit_parcel.php. The manipulation of the argument email leads to sql injection. The exploit has been…

  • CVE-2023-5270MedSep 29, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file view_parcel.php. The manipulation of the argument id leads to sql injection. The exploit has…

  • CVE-2023-5269MedSep 29, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as critical. Affected is an unknown function of the file parcel_list.php of the component GET Parameter Handler. The manipulation of the argument id/s leads to sql injection.…

  • CVE-2023-1736MedMar 30, 2023
    risk 0.36cvss 5.5epss 0.00

    A vulnerability, which was classified as critical, has been found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. Affected by this issue is some unknown functionality of the file cart/controller.php?action=add. The manipulation of the argument PROID leads to sql…

  • CVE-2023-1506MedMar 20, 2023
    risk 0.36cvss 5.6epss 0.01

    A vulnerability, which was classified as critical, was found in SourceCodester E-Commerce System 1.0. Affected is an unknown function of the file login.php. The manipulation of the argument U_USERNAME leads to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2023-1504MedMar 20, 2023
    risk 0.36cvss 5.6epss 0.01

    A vulnerability classified as critical was found in SourceCodester Alphaware Simple E-Commerce System 1.0. This vulnerability affects unknown code. The manipulation of the argument email/password with the input test1%40test.com ' AND (SELECT 6077 FROM (SELECT(SLEEP(5)))dltn) AND…

  • CVE-2023-1503MedMar 20, 2023
    risk 0.36cvss 5.6epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Alphaware Simple E-Commerce System 1.0. This affects an unknown part of the file admin/admin_index.php. The manipulation of the argument username/password with the input admin' AND (SELECT 8062 FROM…

  • CVE-2023-1502MedMar 20, 2023
    risk 0.36cvss 5.6epss 0.01

    A vulnerability was found in SourceCodester Alphaware Simple E-Commerce System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file function/edit_customer.php. The manipulation of the argument firstname/mi/lastname with the input…

  • CVE-2023-1455MedMar 17, 2023
    risk 0.36cvss 5.6epss 0.01

    A vulnerability classified as critical was found in SourceCodester Online Pizza Ordering System 1.0. This vulnerability affects unknown code of the file admin/ajax.php?action=login2 of the component Login Page. The manipulation of the argument email with the input abc%40qq.com'…

  • CVE-2023-1352MedMar 11, 2023
    risk 0.36cvss 5.6epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Design and Implementation of Covid-19 Directory on Vaccination System 1.0. This issue affects some unknown processing of the file /admin/login.php. The manipulation of the argument…

  • CVE-2023-1057MedFeb 27, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Doctors Appointment System 1.0. It has been rated as critical. Affected by this issue is the function edoc of the file login.php. The manipulation of the argument usermail leads to sql injection. VDB-221822 is the identifier assigned…

  • CVE-2023-0707MedFeb 7, 2023
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was found in SourceCodester Medical Certificate Generator App 1.0. It has been rated as critical. Affected by this issue is the function delete_record of the file function.php. The manipulation of the argument id leads to sql injection. VDB-220346 is the…

  • CVE-2023-0516MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. Affected is an unknown function of the file user/forget_password.php of the component Parameter Handler. The manipulation of the argument email leads to…

  • CVE-2023-0515MedJan 26, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0 and classified as critical. This issue affects some unknown processing of the file admin/forget_password.php of the component Parameter Handler. The manipulation of the argument email leads…

  • CVE-2022-2708MedAug 8, 2022
    risk 0.36cvss 5.5epss 0.01

    A vulnerability, which was classified as critical, was found in SourceCodester Gym Management System. This affects an unknown part of the file login.php. The manipulation of the argument user_login with the input [email protected]' OR (SELECT 9084 FROM(SELECT…

  • CVE-2022-2644MedAug 4, 2022
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Online Admission System and classified as critical. This issue affects some unknown processing of the component GET Parameter Handler. The manipulation of the argument eid leads to sql injection. The exploit has been disclosed to the…

  • CVE-2026-5812MedApr 8, 2026
    risk 0.35cvss 5.4epss 0.00

    A security flaw has been discovered in SourceCodester Pharmacy Product Management System 1.0. This affects an unknown part of the file add-sales.php of the component POST Parameter Handler. Performing a manipulation of the argument txtqty results in business logic errors. It is…

  • CVE-2026-5811MedApr 8, 2026
    risk 0.35cvss 5.4epss 0.00

    A vulnerability was identified in SourceCodester Online Food Ordering System 1.0. Affected by this issue is the function save_product of the file /Actions.php of the component POST Parameter Handler. Such manipulation of the argument price leads to business logic errors. The…

  • CVE-2026-30520MedMar 31, 2026
    risk 0.35cvss 5.4epss 0.00

    A Blind SQL Injection vulnerability exists in SourceCodester Loan Management System v1.0. The vulnerability is located in the ajax.php file (specifically the save_loan action). The application fails to properly sanitize user input supplied to the "borrower_id" parameter in a…

  • CVE-2026-30527MedMar 27, 2026
    risk 0.35cvss 5.4epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Category management module within the admin panel. The application fails to properly sanitize user input supplied to the "Category Name" field when creating or…

  • CVE-2026-3761MedMar 8, 2026
    risk 0.35cvss 5.4epss 0.00

    A flaw has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /superadmin_user_delete.php of the component Endpoint. Executing a manipulation of the argument user_id can lead to improper authorization. The…

  • CVE-2025-70458MedJan 23, 2026
    risk 0.35cvss 5.4epss 0.00

    A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sourcecodester Domain Availability Checker v1.0. The vulnerability occurs because the application improperly handles user-supplied data in the createResultElement…

  • CVE-2025-64070MedDec 2, 2025
    risk 0.35cvss 5.4epss 0.00

    Sourcecodester Student Grades Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the Add New Subject Description field.

Page 33 of 51