VYPR

Vendor CVEs

Sourcecodester

All CVEs

2,501 total · sorted by risk
  • CVE-2022-37139MedSep 14, 2022
    risk 0.35cvss 5.4epss 0.01

    Loan Management System version 1.0 suffers from a persistent cross site scripting vulnerability.

  • CVE-2022-36668MedSep 14, 2022
    risk 0.35cvss 5.4epss 0.01

    Garage Management System 1.0 is vulnerable to Stored Cross Site Scripting (XSS) on several parameters. The vulnerabilities exist during creating or editing the parts under parameters. Using the XSS payload, the Stored XSS triggered and can be used for further attack vector.

  • CVE-2022-36639MedSep 2, 2022
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability in /client.php of Garage Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.

  • CVE-2022-36638MedSep 2, 2022
    risk 0.35cvss 5.3epss 0.01

    An access control issue in the component print.php of Garage Management System v1.0 allows unauthenticated attackers to access data for all existing orders.

  • CVE-2022-36637MedSep 2, 2022
    risk 0.35cvss 5.4epss 0.01

    Garage Management System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via the brand_name parameter at /brand.php.

  • CVE-2022-37150MedAug 26, 2022
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Online Diagnostic Lab Management System 1.0. There is a stored XSS vulnerability via firstname, address, middlename, lastname , gender, email, contact parameters.

  • CVE-2022-2776MedAug 11, 2022
    risk 0.35cvss 5.4epss 0.01

    A vulnerability classified as problematic has been found in SourceCodester Gym Management System. Affected is an unknown function of the file delete_user.php. The manipulation of the argument delete_user leads to denial of service. It is possible to launch the attack remotely.…

  • CVE-2020-36553MedJul 15, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Area(food_type) field to /dashboard/menu-list.php.

  • CVE-2020-36552MedJul 15, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Made field to /dashboard/menu-list.php.

  • CVE-2020-36551MedJul 15, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Item Name field to /dashboard/menu-list.php.

  • CVE-2020-36550MedJul 15, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Table Name field to /dashboard/table-list.php.

  • CVE-2020-35261MedJul 15, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in sourcecodester Multi Restaurant Table Reservation System 1.0 via the Restaurant Name field to /dashboard/profile.php.

  • CVE-2022-33075MedJul 5, 2022
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability in the Add Classification function of Zoo Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via unspecified vectors.

  • CVE-2021-46824MedJun 23, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in sourcecodester School File Management System 1.0 via the Lastname parameter to the Update Account form in student_profile.php.

  • CVE-2022-30017MedMay 23, 2022
    risk 0.35cvss 5.4epss 0.01

    Rescue Dispatch Management System 1.0 suffers from Stored XSS, leading to admin account takeover via cookie stealing.

  • CVE-2021-43712MedMay 9, 2022
    risk 0.35cvss 5.4epss 0.01

    Stored XSS in Add New Employee Form in Sourcecodester Employee Daily Task Management System 1.0 Allows Remote Attacker to Inject/Store Arbitrary Code via the Name Field.

  • CVE-2021-43633MedApr 14, 2022
    risk 0.35cvss 5.4epss 0.01

    Sourcecodester Messaging Web Application 1.0 is vulnerable to stored XSS. If a sender inserts valid scripts into the chat, the script will be executed on the receiver chat.

  • CVE-2021-43505MedMar 31, 2022
    risk 0.35cvss 5.4epss 0.01

    Multiple Cross Site Scripting (XSS) vulnerabilities exist in Ssourcecodester Simple Client Management System v1 via (1) Add new Client and (2) Add new invoice.

  • CVE-2021-45866MedMar 29, 2022
    risk 0.35cvss 5.4epss 0.01

    A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Student Attendance Management System 1.0 via the couse filed in index.php.

  • CVE-2021-34073MedJan 28, 2022
    risk 0.35cvss 5.4epss 0.01

    A Cross Site Scripting (XSS) vulnerabilty exists in Sourcecodester Gadget Works Online Ordering System in PHP/MySQLi 1.0 via the Category parameter in an add function in category/index.php.

  • CVE-2021-41658MedJan 24, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) in Sourcecodester Student Quarterly Grading System by oretnom23, allows attackers to execute arbitrary code via the fullname and username parameters to the users page.

  • CVE-2022-22296MedJan 24, 2022
    risk 0.35cvss 5.3epss 0.01

    Sourcecodester Hospital's Patient Records Management System 1.0 is vulnerable to Insecure Permissions via the id parameter in manage_user endpoint. Simply change the value and data of other users can be displayed.

  • CVE-2021-44091MedJan 20, 2022
    risk 0.35cvss 5.4epss 0.01

    A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in register.php via the (1) fullname, (2) phone, and (3) address parameters.

  • CVE-2021-46005MedJan 18, 2022
    risk 0.35cvss 5.4epss 0.03

    Sourcecodester Car Rental Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via vehicalorcview parameter.

  • CVE-2021-42664MedNov 5, 2021
    risk 0.35cvss 5.4epss 0.02

    A Stored Cross Site Scripting (XSS) Vulneraibiilty exists in Sourcecodester Engineers Online Portal in PHP via the (1) Quiz title and (2) quiz description parameters to add_quiz.php. An attacker can leverage this vulnerability in order to run javascript commands on the web…

  • CVE-2021-42662MedNov 5, 2021
    risk 0.35cvss 5.4epss 0.02

    A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Event Booking and Reservation System in PHP/MySQL via the Holiday reason parameter. An attacker can leverage this vulnerability in order to run javascript commands on the web server surfers behalf,…

  • CVE-2021-37805MedOct 27, 2021
    risk 0.35cvss 5.4epss 0.01

    A Stored Cross Site Scripting (XSS) vunerability exists in Sourcecodeste Vehicle Parking Management System affected version 1.0 is via the add-vehicle.php endpoint.

  • CVE-2021-38752MedAug 16, 2021
    risk 0.35cvss 5.4epss 0.01

    A cross-site scripting (XSS) vulnerability in Online Catering Reservation System using PHP on Sourcecodester allows an attacker to arbitrarily inject code in the search bar.

  • CVE-2021-25790MedJul 23, 2021
    risk 0.35cvss 5.4epss 0.01

    Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate…

  • CVE-2021-25204MedJul 23, 2021
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in SourceCodester E-Commerce Website v 1.0 allows remote attackers to inject arbitrary web script or HTM via the subject field to feedback_process.php.

  • CVE-2020-29215MedJun 15, 2021
    risk 0.35cvss 5.4epss 0.01

    A Cross Site Scripting in SourceCodester Employee Management System 1.0 allows the user to execute alert messages via /Employee Management System/addemp.php on admin account.

  • CVE-2021-29388MedApr 28, 2021
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in SourceCodester Budget Management System 1.0 allows users to inject and store arbitrary JavaScript code in index.php via vulnerable field 'Budget Title'.

  • CVE-2021-29387MedApr 28, 2021
    risk 0.35cvss 5.4epss 0.01

    Multiple stored cross-site scripting (XSS) vulnerabilities in Sourcecodester Equipment Inventory System 1.0 allow remote attackers to inject arbitrary javascript via any "Add" sections, such as Add Item , Employee and Position or others in the Name Parameters.

  • CVE-2020-35752MedMar 10, 2021
    risk 0.35cvss 5.4epss 0.01

    Baby Care System 1.0 is affected by a cross-site scripting (XSS) vulnerability in the Edit Page tab through the Post title parameter.

  • CVE-2020-25955MedDec 8, 2020
    risk 0.35cvss 5.4epss 0.01

    SourceCodester Student Management System Project in PHP version 1.0 is vulnerable to stored a cross-site scripting (XSS) via the 'add subject' tab.

  • CVE-2026-19987MedAug 17, 2026
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in SourceCodester Best Employee Management System 1.0. This affects an unknown function of the file /assets/uploadImage/Profile/. Such manipulation leads to exposure of information through directory listing. It is possible to launch the…

  • CVE-2026-19903MedAug 15, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db/shopping.sql of the component SQL Database Backup. The manipulation leads to files or directories accessible. Remote exploitation of the attack is possible.…

  • CVE-2026-19229MedAug 7, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functionality of the file /_notes/ of the component Dreamweaver Metadata Files. Executing a manipulation can lead to file and directory information exposure. The attack…

  • CVE-2026-11552MedJun 8, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System and Syllabus-aligned Learning Management and Examination System 1.0. Affected by this issue is some unknown functionality of the file import_users.php. The manipulation of the…

  • CVE-2026-11515MedJun 8, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in SourceCodester Barangay Resident Profiling and Information Management System 1.0. The impacted element is an unknown function of the file passsword_reset.php of the component Password Reset Handler. Such manipulation of the argument new_password…

  • CVE-2026-10255MedJun 1, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function sell_statement of the file application/controllers/ShowForm.php. Such manipulation leads to improper access controls. The attack can be…

  • CVE-2026-10254MedJun 1, 2026
    risk 0.34cvss 5.3epss 0.00

    A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/. This manipulation causes file and directory information exposure. The attack can be initiated remotely. The exploit has been published and may be…

  • CVE-2026-5531MedApr 5, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function of the file /login_credentials.txt of the component HTTP GET Request Handler. The manipulation leads to cleartext storage in a file or on disk. The attack may…

  • CVE-2026-5326MedApr 2, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was identified in SourceCodester Leave Application System 1.0. Impacted is an unknown function of the file /index.php?page=manage_user of the component User Information Handler. Such manipulation of the argument ID leads to authorization bypass. The attack can be…

  • CVE-2026-3817MedMar 9, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. This issue affects some unknown processing of the file /patient-search.php. The manipulation results in improper authorization. The attack can be launched remotely. The exploit is…

  • CVE-2025-13565MedNov 23, 2025
    risk 0.34cvss 5.3epss 0.00

    A weakness has been identified in SourceCodester Inventory Management System 1.0. The affected element is an unknown function of the file /model/user/resetPassword.php. Executing manipulation can lead to weak password recovery. The attack may be performed from remote. The…

  • CVE-2025-13200MedNov 15, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was determined in SourceCodester Farm Management System 1.0. Affected by this vulnerability is an unknown functionality. This manipulation causes exposure of information through directory listing. The attack is possible to be carried out remotely. The exploit has…

  • CVE-2025-5649MedJun 5, 2025
    risk 0.34cvss 5.3epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /admin/core/new_user of the component Register Interface. The manipulation leads to improper access controls. It is possible to…

  • CVE-2025-5297MedMay 28, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability, which was classified as critical, has been found in SourceCodester Computer Store System 1.0. This issue affects the function Add of the file main.c. The manipulation of the argument laptopcompany/RAM/Processor leads to stack-based buffer overflow. An attack has…

  • CVE-2025-3763MedApr 17, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability classified as critical has been found in SourceCodester Phone Management System 1.0. This affects the function main of the component Password Handler. The manipulation of the argument s leads to buffer overflow. Local access is required to approach this attack.…

Page 35 of 51