VYPR

Vendor CVEs

Sourcecodester

All CVEs

2,498 total · sorted by risk
  • CVE-2019-18280HigOct 23, 2019
    risk 0.57cvss 8.8epss 0.00

    Sourcecodester Online Grading System 1.0 is affected by a Cross Site Request Forgery vulnerability due to a lack of CSRF protection. This could lead to an attacker tricking the administrator into executing arbitrary code via a crafted HTML page, as demonstrated by a Create User…

  • CVE-2025-45997HigMay 28, 2025
    risk 0.56cvss 8.6epss 0.00

    Sourcecodester Web-based Pharmacy Product Management System v.1.0 has a file upload vulnerability. An attacker can upload a PHP file disguised as an image by modifying the Content-Type header to image/jpg.

  • CVE-2024-31507HigApr 9, 2024
    risk 0.56cvss 8.6epss 0.00

    Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "request" parameter in admin/fetch_gendercs.php.

  • CVE-2023-33676HigMar 7, 2024
    risk 0.55cvss 8.4epss 0.01

    Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*" which can be escalated to the remote command execution.

  • CVE-2020-25514HigSep 22, 2020
    risk 0.55cvss 8.4epss 0.01

    Sourcecodester Simple Library Management System 1.0 is affected by Incorrect Access Control via the Login Panel, http:///lms/admin.php.

  • CVE-2026-30534HigMar 27, 2026
    risk 0.54cvss 8.3epss 0.00

    A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via the "id" parameter.

  • CVE-2025-63298HigOct 30, 2025
    risk 0.53cvss 8.2epss 0.00

    A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting the admin/manage_website.php component. An authenticated user with administrative privileges can leverage this flaw by submitting a specially crafted POST request,…

  • CVE-2024-36569HigJun 3, 2024
    risk 0.53cvss 8.1epss 0.01

    Sourcecodester Gas Agency Management System v1.0 is vulnerable to arbitrary code execution via editClientImage.php.

  • CVE-2024-33303HigMay 2, 2024
    risk 0.53cvss 8.2epss 0.01

    SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" under Add Users.

  • CVE-2023-24317HigFeb 23, 2023
    risk 0.53cvss 8.1epss 0.01

    Judging Management System 1.0 was discovered to contain an arbitrary file upload vulnerability via the component edit_organizer.php.

  • CVE-2021-37803HigOct 27, 2021
    risk 0.53cvss 8.1epss 0.02

    An SQL Injection vulnerability exists in Sourcecodester Online Covid Vaccination Scheduler System 1.0 via the username in lognin.php .

  • CVE-2021-36621HigJul 30, 2021
    risk 0.53cvss 8.1epss 0.02

    Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection. The username parameter is vulnerable to time-based SQL injection. Upon successful dumping the admin password hash, an attacker can decrypt and obtain the plain-text password. Hence, the…

  • CVE-2024-40476HigAug 12, 2024
    risk 0.52cvss 8.0epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability was found in SourceCodester Best House Rental Management System v1.0. This could lead to an attacker tricking the administrator into adding/modifying/deleting valid tenant data via a crafted HTML page, as demonstrated by a Delete…

  • CVE-2023-33440HigMay 26, 2023
    risk 0.51cvss 7.2epss 0.15

    Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user.

  • CVE-2023-0963HigFeb 22, 2023
    risk 0.51cvss 7.3epss 0.05

    A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file Users.php of the component POST Request Handler. The manipulation leads to improper access controls. The attack may be…

  • CVE-2023-0905HigFeb 18, 2023
    risk 0.51cvss 7.3epss 0.03

    A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is an unknown function of the file changePasswordForEmployee.php. The manipulation leads to improper authentication. It is possible to launch the attack…

  • CVE-2022-44830HigNov 21, 2022
    risk 0.51cvss 7.8epss 0.01

    Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.

  • CVE-2020-25515HigSep 22, 2020
    risk 0.51cvss 7.8epss 0.01

    Sourcecodester Simple Library Management System 1.0 is affected by Insecure Permissions via Books > New Book , http:///lms/index.php?page=books.

  • CVE-2022-4855HigDec 30, 2022
    risk 0.50cvss 7.3epss 0.25

    A vulnerability, which was classified as critical, was found in SourceCodester Lead Management System 1.0. Affected is an unknown function of the file login.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2021-42671HigNov 5, 2021
    risk 0.50cvss 7.5epss 0.20

    An incorrect access control vulnerability exists in Sourcecodester Engineers Online Portal in PHP in nia_munoz_monitoring_system/admin/uploads. An attacker can leverage this vulnerability in order to bypass access controls and access all the files uploaded to the web server…

  • CVE-2026-30573HigApr 1, 2026
    risk 0.49cvss 7.5epss 0.00

    A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is located in the add-sales.php file. The application fails to validate the "txtprice" and "txttotalcost" parameters, allowing attackers to submit negative values…

  • CVE-2026-30576HigMar 27, 2026
    risk 0.49cvss 7.5epss 0.00

    A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file. The application fails to validate the "txtprice" and "txttotalcost" parameters during stock entry, allowing negative financial values to be submitted. This…

  • CVE-2026-30575HigMar 27, 2026
    risk 0.49cvss 7.5epss 0.00

    A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file. The application fails to validate the "txtqty" parameter during stock entry, allowing negative values to be processed. This causes the system to decrease the…

  • CVE-2026-30574HigMar 27, 2026
    risk 0.49cvss 7.5epss 0.00

    A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file. The application fails to verify if the requested sales quantity (txtqty) exceeds the available stock level. An attacker can manipulate the request to…

  • CVE-2025-63891HigNov 14, 2025
    risk 0.49cvss 7.5epss 0.00

    Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote unauthenticated attacker to disclose full database contents (including schema and credential hashes) via an unauthenticated HTTP GET request to…

  • CVE-2025-44193HigApr 30, 2025
    risk 0.49cvss 7.6epss 0.00

    SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_complaint.

  • CVE-2024-34220HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.01

    Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter.

  • CVE-2024-31506HigApr 9, 2024
    risk 0.49cvss 7.5epss 0.01

    Sourcecodester Online Graduate Tracer System v1.0 is vulnerable to SQL Injection via the "id" parameter in admin/admin_cs.php.

  • CVE-2024-29302HigMar 26, 2024
    risk 0.49cvss 7.5epss 0.01

    SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-employee.php.

  • CVE-2024-29301HigMar 26, 2024
    risk 0.49cvss 7.5epss 0.01

    SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-admin.php?admin_id=

  • CVE-2023-49981HigMar 21, 2024
    risk 0.49cvss 7.5epss 0.01

    A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.

  • CVE-2023-49980HigMar 21, 2024
    risk 0.49cvss 7.5epss 0.01

    A directory listing vulnerability in Best Student Result Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.

  • CVE-2023-33677HigMar 6, 2024
    risk 0.49cvss 7.5epss 0.00

    Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*".

  • CVE-2023-49545HigMar 1, 2024
    risk 0.49cvss 7.5epss 0.01

    A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.

  • CVE-2024-0264HigJan 7, 2024
    risk 0.49cvss 7.3epss 0.18

    A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /LoginRegistration.php. The manipulation of the argument formToken leads to authorization bypass. The attack can be…

  • CVE-2021-34249HigFeb 24, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive information via the id paremeter in application URL.

  • CVE-2023-0324HigJan 16, 2023
    risk 0.49cvss 7.3epss 0.19

    A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/page-login.php. The manipulation of the argument email leads to sql injection. The attack…

  • CVE-2022-40049HigJan 6, 2023
    risk 0.49cvss 7.5epss 0.01

    SQL injection vulnerability in sourcecodester Theme Park Ticketing System 1.0 allows remote attackers to view sensitive information via the id parameter to the /tpts/manage_user.php page.

  • CVE-2022-37151HigAug 26, 2022
    risk 0.49cvss 7.5epss 0.01

    There is an unauthorized access vulnerability in Online Diagnostic Lab Management System 1.0.

  • CVE-2021-45348HigFeb 14, 2022
    risk 0.49cvss 7.5epss 0.01

    An Arbitrary File Deletion vulnerability exists in SourceCodester Attendance Management System v1.0 via the csv parameter in admin/pageUploadCSV.php, which can cause a Denial of Service (crash).

  • CVE-2020-24862HigJun 2, 2021
    risk 0.49cvss 7.5epss 0.02

    The catID parameter in Pharmacy Medical Store and Sale Point v1.0 has been found to be vulnerable to a Time-Based blind SQL injection via the /medical/inventories.php path which allows attackers to retrieve all databases.

  • CVE-2020-36003HigFeb 17, 2021
    risk 0.49cvss 7.5epss 0.01

    The id parameter in detail.php of Online Book Store v1.0 is vulnerable to union-based blind SQL injection, which leads to the ability to retrieve all databases.

  • CVE-2024-33288HigMay 8, 2026
    risk 0.48cvss 7.3epss 0.01

    Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the Admin login page.

  • CVE-2025-4468HigMay 9, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Online Student Clearance System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /edit-photo.php. The manipulation of the argument userImage leads to unrestricted upload. The attack may be…

  • CVE-2025-4467HigMay 9, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Online Student Clearance System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/edit-admin.php. The manipulation of the argument id/txtfullname/txtemail/cmddesignation leads to sql…

  • CVE-2025-3729HigApr 16, 2025
    risk 0.48cvss 7.3epss 0.03

    A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. This issue affects some unknown processing of the file backup.php of the component Database Backup Handler. The manipulation of the argument…

  • CVE-2025-1160HigFeb 10, 2025
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file index.php. The manipulation of the argument username/password leads to use of default credentials. The…

  • CVE-2024-10335HigOct 24, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Garbage Collection Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack can be…

  • CVE-2024-9818HigOct 10, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Online Veterinary Appointment System 1.0. Affected is an unknown function of the file /admin/categories/manage_category.php. The manipulation of the argument id leads to sql injection. It is possible to…

  • CVE-2024-9296HigSep 28, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Advocate Office Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /control/forgot_pass.php. The manipulation of the argument username leads to sql injection. It is possible to launch…

Page 6 of 50