VYPR

Vendor CVEs

Sourcecodester

All CVEs

2,501 total · sorted by risk
  • CVE-2025-13564MedNov 23, 2025
    risk 0.35cvss 5.4epss 0.00

    A security flaw has been discovered in SourceCodester Pre-School Management System 1.0. Impacted is the function removefile of the file app/controllers/FilehelperController.php. Performing manipulation of the argument filepath results in denial of service. The attack is possible…

  • CVE-2025-13468MedNov 20, 2025
    risk 0.35cvss 5.4epss 0.00

    A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_forum/delete_career/delete_comment/delete_gallery/delete_event of the file admin/admin_class.php of the component Delete Handler. Executing manipulation of the…

  • CVE-2025-63709MedNov 10, 2025
    risk 0.35cvss 5.4epss 0.00

    A Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Simple To-Do List System 1.0 in the "Add Tasks" text input. An authenticated user can submit HTML/JavaScript that is not correctly sanitized or encoded on output. The injected script is stored and later rendered…

  • CVE-2025-4912MedMay 19, 2025
    risk 0.35cvss 5.4epss 0.01

    A vulnerability has been found in SourceCodester Student Result Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/core/update_student.php of the component Image File Handler. The manipulation of the…

  • CVE-2025-4898MedMay 18, 2025
    risk 0.35cvss 5.4epss 0.01

    A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as critical. This vulnerability affects the function unlink of the file update_system.php of the component Logo File Handler. The manipulation of the argument old_logo leads to…

  • CVE-2025-4807MedMay 16, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, was found in SourceCodester Online Student Clearance System 1.0. This affects an unknown part. The manipulation leads to exposure of information through directory listing. It is possible to initiate the attack remotely. The…

  • CVE-2025-4720MedMay 15, 2025
    risk 0.35cvss 5.4epss 0.01

    A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file academic/core/drop_student.php. The manipulation of the argument img leads to path traversal. The attack can be…

  • CVE-2025-44185MedMay 15, 2025
    risk 0.35cvss 5.4epss 0.00

    SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/change_pass.php via the password parameter.

  • CVE-2025-44186MedMay 14, 2025
    risk 0.35cvss 5.4epss 0.00

    SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operation/User.php page.

  • CVE-2024-40069MedApr 16, 2025
    risk 0.35cvss 5.4epss 0.00

    Sourcecodester Online ID Generator System 1.0 was discovered to contain Stored Cross Site Scripting (XSS) via id_generator/classes/Users.php?f=save, and the point of vulnerability is in the POST parameter 'firstname' and 'lastname'.

  • CVE-2025-2652MedMar 23, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to exposure of information through directory listing. The attack…

  • CVE-2025-2651MedMar 23, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /oews/admin/. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack…

  • CVE-2025-1599MedFeb 24, 2025
    risk 0.35cvss 5.4epss 0.01

    A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/app/profile_crud.php. The manipulation of the argument old_cat_img leads to path traversal:…

  • CVE-2024-55000MedJan 14, 2025
    risk 0.35cvss 5.4epss 0.00

    Sourcecodester House Rental Management system v1.0 is vulnerable to Cross Site Scripting (XSS) in rental/manage_categories.php.

  • CVE-2024-51032MedNov 8, 2024
    risk 0.35cvss 5.4epss 0.00

    A Cross-site Scripting (XSS) vulnerability in manage_recipient.php of Sourcecodester Toll Tax Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "owner" input field.

  • CVE-2024-51031MedNov 8, 2024
    risk 0.35cvss 5.4epss 0.00

    A Cross-site Scripting (XSS) vulnerability in manage_account.php in Sourcecodester Cab Management System 1.0 allows remote authenticated users to inject arbitrary web scripts via the "First Name," "Middle Name," and "Last Name" fields.

  • CVE-2024-8711MedSep 12, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in SourceCodester Food Ordering Management System 1.0. Affected by this issue is some unknown functionality of the file /includes/. The manipulation leads to exposure of information through directory listing.…

  • CVE-2024-7843MedAug 15, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, was found in SourceCodester Online Graduate Tracer System 1.0. Affected is an unknown function of the file /tracking/admin/exportcs.php. The manipulation leads to information disclosure. It is possible to launch the attack…

  • CVE-2024-7842MedAug 15, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in SourceCodester Online Graduate Tracer System 1.0. This issue affects some unknown processing of the file /tracking/admin/export_it.php. The manipulation leads to information disclosure. The attack may be…

  • CVE-2024-7813MedAug 15, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. This issue affects some unknown processing of the file /uploadImage/Profile/ of the component Profile Image Handler. The manipulation leads to insufficiently…

  • CVE-2024-7809MedAug 15, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /tracking/nbproject/. The manipulation leads to exposure of information through directory…

  • CVE-2024-7753MedAug 14, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in SourceCodester Clinics Patient Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /user_images/. The manipulation leads to direct request. The attack can be initiated remotely. The exploit…

  • CVE-2024-40474MedAug 12, 2024
    risk 0.35cvss 5.4epss 0.01

    A Reflected Cross Site Scripting (XSS) vulnerability was found in "edit-cate.php" in SourceCodester House Rental Management System v1.0.

  • CVE-2024-40473MedAug 12, 2024
    risk 0.35cvss 5.4epss 0.01

    A Stored Cross Site Scripting (XSS) vulnerability was found in "manage_houses.php" in SourceCodester Best House Rental Management System v1.0. It allows remote attackers to execute arbitrary code via "House_no" and "Description" parameter fields.

  • CVE-2024-7080MedJul 24, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in SourceCodester Insurance Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /E-Insurance/. The manipulation leads to direct request. The attack can be launched remotely.…

  • CVE-2024-35468MedMay 30, 2024
    risk 0.35cvss 5.4epss 0.00

    A SQL injection vulnerability in /hrm/index.php in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.

  • CVE-2023-24204MedMay 14, 2024
    risk 0.35cvss 5.4epss 0.01

    SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitrary code via the name parameter in get-quote.php.

  • CVE-2023-24203MedMay 14, 2024
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitary code via the company or query parameter(s).

  • CVE-2024-33307MedMay 1, 2024
    risk 0.35cvss 5.4epss 0.00

    SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" parameter in Create User.

  • CVE-2023-23019MedMay 1, 2024
    risk 0.35cvss 5.4epss 0.00

    Cross site scripting (XSS) vulnerability in file main.php in sourcecodester oretnom23 Blog Site 1.0 via the name and email parameters to function user_add.\

  • CVE-2024-3139MedApr 1, 2024
    risk 0.35cvss 5.4epss 0.00

    A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue is the function save_users of the file /classes/Users.php?f=save. The manipulation of the argument id leads to improper…

  • CVE-2023-51281MedMar 7, 2024
    risk 0.35cvss 5.4epss 0.00

    Cross Site Scripting vulnerability in Customer Support System v.1.0 allows a remote attacker to escalate privileges via a crafted script firstname, "lastname", "middlename", "contact" and address parameters.

  • CVE-2023-49987MedMar 7, 2024
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability in the component /management/term of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the tname parameter.

  • CVE-2023-46450MedOct 26, 2023
    risk 0.35cvss 5.4epss 0.00

    Sourcecodester Free and Open Source inventory management system 1.0 is vulnerable to Cross Site Scripting (XSS) via the Add supplier function.

  • CVE-2023-43944MedSep 29, 2023
    risk 0.35cvss 5.4epss 0.00

    A Stored Cross Site Scripting (XSS) vulnerability was found in SourceCodester Task Management System 1.0. It allows attackers to execute arbitrary code via parameter field in index.php?page=project_list.

  • CVE-2023-44048MedSep 27, 2023
    risk 0.35cvss 5.4epss 0.00

    Sourcecodester Expense Tracker App v1 is vulnerable to Cross Site Scripting (XSS) via add category.

  • CVE-2023-4181MedAug 6, 2023
    risk 0.35cvss 5.4epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected by this issue is some unknown functionality of the file /vm/admin/delete-doctor.php?id=2 of the component Redirect Handler. The…

  • CVE-2023-31705MedJul 13, 2023
    risk 0.35cvss 5.4epss 0.01

    A Reflected Cross-site scripting (XSS) vulnerability in Sourcecodester Task Reminder System 1.0 allows an authenticated user to inject malicious javascript into the page parameter.

  • CVE-2023-30458MedApr 24, 2023
    risk 0.35cvss 5.3epss 0.01

    A username enumeration issue was discovered in Medicine Tracker System 1.0. The login functionality allows a malicious user to guess a valid username due to a different response time from invalid usernames. When one enters a valid username, the response time increases depending…

  • CVE-2023-27776MedApr 19, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in /index.php?page=category_list of Online Jewelry Shop v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter.

  • CVE-2023-2152MedApr 18, 2023
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument page leads to file inclusion. The…

  • CVE-2023-1956MedApr 8, 2023
    risk 0.35cvss 5.4epss 0.01

    A vulnerability classified as critical was found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=delete_img of the component Image Handler. The manipulation of the argument path…

  • CVE-2023-27242MedMar 24, 2023
    risk 0.35cvss 5.4epss 0.00

    SourceCodester Loan Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Type parameter under the Edit Loan Types module.

  • CVE-2022-4228MedNov 30, 2022
    risk 0.35cvss 5.3epss 0.01

    A vulnerability classified as problematic has been found in SourceCodester Book Store Management System 1.0. This affects an unknown part of the file /bsms_ci/index.php/user/edit_user/. The manipulation of the argument password leads to information disclosure. It is possible to…

  • CVE-2022-43117MedNov 21, 2022
    risk 0.35cvss 5.4epss 0.01

    Sourcecodester Password Storage Application in PHP/OOP and MySQL 1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the Name, Username, Description and Site Feature parameters.

  • CVE-2022-43144MedNov 8, 2022
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting (XSS) vulnerability in Canteen Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2022-3774MedOct 31, 2022
    risk 0.35cvss 5.4epss 0.01

    A vulnerability was found in SourceCodester Train Scheduler App 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /train_scheduler_app/?action=delete. The manipulation of the argument id leads to improper control of resource…

  • CVE-2022-42069MedOct 14, 2022
    risk 0.35cvss 5.4epss 0.00

    Online Birth Certificate Management System version 1.0 suffers from a persistent Cross Site Scripting (XSS) vulnerability.

  • CVE-2022-30003MedSep 26, 2022
    risk 0.35cvss 5.4epss 0.01

    Sourcecodester Online Market Place Site 1.0 is vulnerable to Cross Site Scripting (XSS), allowing attackers to register as a Seller then create new products containing XSS payloads in the 'Product Title' and 'Short Description' fields.

  • CVE-2021-42597MedSep 16, 2022
    risk 0.35cvss 5.4epss 0.00

    A Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Storage Unit Rental Management System PHP 8.0.10 , Apache 2.4.14, SURMS V 1.0 via the Add New Tenant List Rent List form.

Page 34 of 51