Sourcecodester
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Sourcecodester product.
RSS Feeds for Sourcecodester security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Sourcecodester products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Sourcecodester Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 383 vulnerabilities in Sourcecodester with an average score of 6.0 out of ten. Last year, in 2025 Sourcecodester had 132 security vulnerabilities published. That is, 251 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.34
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 383 | 6.00 |
| 2025 | 132 | 6.33 |
| 2024 | 15 | 6.27 |
| 2023 | 1 | 7.20 |
| 2022 | 2 | 9.80 |
| 2021 | 6 | 8.45 |
| 2020 | 0 | 0.00 |
| 2019 | 2 | 0.00 |
It may take a day or so for new Sourcecodester vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Sourcecodester Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-95957 | Sep 23, 2026 |
SourceCodester Smart Attendance System 1.0 Self-Registration XSS via full_nameA vulnerability was found in SourceCodester Smart Attendance System with QR Code Scanner 1.0. This issue affects the function prepend of the file student_signup.php of the component Self-Registration. Performing a manipulation of the argument full_name results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and could be used. |
|
| CVE-2026-95927 | Sep 23, 2026 |
SourceCodester OSM 1.0 SQLi in admin/assessments/pretest/exam-delete.phpA vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/pretest/exam-delete.php. Such manipulation of the argument test_id leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. |
|
| CVE-2026-95926 | Sep 23, 2026 |
SQLi in SourceCodester Online Reviewer Mgmt System 1.0 (btn_funcs.php)A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admins/assessments/pretest/btn_functions.php?action=update. This manipulation of the argument test_id causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-95925 | Sep 23, 2026 |
SQLi in SourceCodester Online Reviewer Management System 1.0 via difficulty_idA vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=update. The manipulation of the argument difficulty_id results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. |
|
| CVE-2026-95924 | Sep 23, 2026 |
SQLi in SourceCodester Online Reviewer Management System 1.0A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=add. The manipulation of the argument difficulty_id leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-94035 | Sep 20, 2026 |
SourceCodester Drug Recommendation System 1.0 XSS via full name in index.phpA vulnerability was determined in SourceCodester Drug Recommendation System 1.0. Impacted is an unknown function of the file /drug_recommender/index.php. Executing a manipulation of the argument full name can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-94034 | Sep 20, 2026 |
CVE-2026-94034: Reflected XSS via pwd change in SDRS 1.0A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /drug_recommender/Admin/change_password of the component Password Change. Performing a manipulation of the argument txtoldpassword/txtnewpassword results in cross site scripting. The attack can be initiated remotely. The exploit has been made public and could be used. |
|
| CVE-2026-94033 | Sep 20, 2026 |
XSS via add_user in SourceCodester Drug Recommendation System 1.0 (Remote)A vulnerability has been found in SourceCodester Drug Recommendation System 1.0. This vulnerability affects unknown code of the file /drug_recommender/Admin/add_user of the component User Management. Such manipulation of the argument txtname/txtemail/txtpassword leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-94016 | Sep 20, 2026 |
XSS in SourceCodester Drug Recommendation System 1.0 via add_symptomA security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file /drug_recommender/Admin/add_symptom. Performing a manipulation of the argument txtname results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-94015 | Sep 20, 2026 |
SQL Injection in SourceCodester Drug Recommender 1.0 edit_user.phpA vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the file /drug_recommender/Admin/edit_user.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-93997 | Sep 20, 2026 |
SrcCodester DR System 1.0 Remote SQLi in edit_symptom.phpA weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected by this issue is some unknown functionality of the file /Admin/edit_symptom.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-93974 | Sep 20, 2026 |
SQLi via btn_functions.php in SourceCodester Online Reviewer System 1.0A flaw has been found in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=remove. Executing a manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used. |
|
| CVE-2026-93973 | Sep 20, 2026 |
SourceCodester Online Reviewer Mgmt Sys 1.0 SQLi via btn_functions.phpA vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admins/assessments/subject/btn_functions.php?action=remove. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used. |
|
| CVE-2026-93972 | Sep 20, 2026 |
SQL Injection in SourceCodester Online Reviewer Mgmt 1.0 via btn_functions.phpA security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/course/btn_functions.php. Such manipulation of the argument courseID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-93959 | Sep 20, 2026 |
SQLi via Course param in btn_functions.php of SCM System 1.0A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/course/btn_functions.php. This manipulation of the argument Course causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-92927 | Sep 17, 2026 |
Info Disclosure via /db/drug_recommendor.sql in SourceCodester Drug Recomm 1.0A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /db/drug_recommendor.sql. Performing a manipulation results in information disclosure. The attack is possible to be carried out remotely. The exploit has been made public and could be used. |
|
| CVE-2026-92406 | Sep 16, 2026 |
A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown function of the file /admins/assessments/databank/btn_functions.php?action=add. Performing a manipulation of the argument difficulty_id results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. |
|
| CVE-2026-92405 | Sep 16, 2026 |
A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element is an unknown function of the file /index.php. Such manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-92385 | Sep 16, 2026 |
A vulnerability has been found in SourceCodester Online Food Ordering System 1.0A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/update_category.php of the component Category Update. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-91005 | Sep 15, 2026 |
SourceCodester Online Faculty Clearance System 1.0 Unrestricted File UploadA vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file of the file production/edit_picture.php of the component Profile Picture Upload. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public and could be used. |
|
| CVE-2026-91004 | Sep 15, 2026 |
SQLi in SourceCodester Online Faculty Clearance 1.0 delete_faculty1.phpA vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /delete_faculty1.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-90877 | Sep 15, 2026 |
SourceCodester Faculty Clearance 1.0 SQLi in update_requirement_status.phpA vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this issue is some unknown functionality of the file /update_requirement_status.php. The manipulation of the argument haydi results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. |
|
| CVE-2026-90876 | Sep 15, 2026 |
SQLi in SourceCodester OCSC 1.0 via /delete_requirement.php IDA vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_requirement.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-90857 | Sep 15, 2026 |
Unrestricted Upload in SCGMGMS 1.0 via Profile Upload Remote ExploitA vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0. Affected is an unknown function of the file /dashboard/userprofile.php of the component Profile Upload. Performing a manipulation of the argument image results in unrestricted upload. The attack may be initiated remotely. The exploit is now public and may be used. |
|
| CVE-2026-90856 | Sep 15, 2026 |
SourceCodester Gallery Mgmt Sys 1.0 Privilege Escalation via Role in signup.phpA security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts an unknown function of the file signup.php of the component Registration Flow. Such manipulation of the argument role leads to improper privilege management. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-90855 | Sep 15, 2026 |
SQLi in SourceCodester katojkalemba OOS 1.0 via /web/order.php ID paramA weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0. This affects an unknown function of the file /web/order.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-90854 | Sep 15, 2026 |
SQLi in SourceCodester/katojkalemba Food Ordering System 1.0 /web/category-foods.phpA security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted element is an unknown function of the file /web/category-foods.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-90849 | Sep 15, 2026 |
SQLi via User param in SourceCodester College Notes Gallery Management System 1.0 login.phpA security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /College/login.php. The manipulation of the argument User leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-90697 | Sep 14, 2026 |
Auth Bypass via ID in invoice.php of SourceCodester IMS 1.0A vulnerability was identified in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file invoice.php. The manipulation of the argument ID leads to authorization bypass. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-90696 | Sep 14, 2026 |
CVE-2026-90696: XSS in SC Inventory Mgt 1.0 (api/products_handler.php)A vulnerability was determined in SourceCodester Inventory Management System 1.0. Affected by this issue is some unknown functionality of the file /api/products_handler.php of the component Product Management Module. Executing a manipulation of the argument Product_Name can lead to cross site scripting. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-90695 | Sep 14, 2026 |
SourceCodester Inventory Management System 1.0 XSS in Vendor Management APIA vulnerability was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /api/vendors_handler.php of the component Vendor Management. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used. |
|
| CVE-2026-90694 | Sep 14, 2026 |
SourceCodester Inventory 1.0 XSS in /api/customers_handler.phpA vulnerability has been found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file /api/customers_handler.php of the component Customer Management Module. Such manipulation of the argument Customer_Name leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-90615 | Sep 14, 2026 |
SourceCodester Class & Exam Timetabling System 1.0 XSS via subject1.phpA security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /subject1.php. Such manipulation of the argument subject leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-90526 | Sep 13, 2026 |
SQLi in SourceCodester School Reg & Fee System 1.0 via CategoryA security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unknown function of the file /bilal/save_class.php. The manipulation of the argument Category leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-90516 | Sep 13, 2026 |
SQLi in SourceCodester School Reg & Fee System 1.0 via /bilal/normal/pay_report.phpA vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown function of the file /bilal/normal/pay_report.php. Performing a manipulation of the argument period results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. |
|
| CVE-2026-90515 | Sep 13, 2026 |
Remote SQLi Vulnerability in SourceCodester School Reg 1.0 delete_stud.phpA vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown function of the file /bilal/normal/delete_stud.php. Executing a manipulation of the argument selector[] can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-90514 | Sep 13, 2026 |
SQLi in SourceCodester School Reg & Fee Sys 1.0 via Status param in save_stud.phpA vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Status leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-86298 | Sep 07, 2026 |
SQLi in SourceCodester Class & Exam Timetabling 1.0 via delete_subject.phpA security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /delete_subject.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-86294 | Sep 07, 2026 |
SourceCodester Simple Traffic Offense System 1.0 XSS via site_name/site_descA vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of the component Settings Update Endpoint. The manipulation of the argument site_name/site_desc leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-86293 | Sep 07, 2026 |
Auth Bypass via ID Manipulation in Traffic Offense System 1.0 Deletion EndpointA flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is an unknown functionality of the file delete-user.php of the component Deletion Endpoint. Executing a manipulation of the argument ID can lead to missing authentication. The attack may be launched remotely. The exploit has been published and may be used. |
|
| CVE-2026-86292 | Sep 07, 2026 |
Missing Auth in SCTOS 1.0 via saveuser.php Remote (Public Exploit)A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown function of the file saveuser.php of the component User Creation. Performing a manipulation of the argument position results in missing authentication. The attack may be initiated remotely. The exploit is now public and may be used. |
|
| CVE-2026-86290 | Sep 07, 2026 |
SourceCodester Online Voting 1.0 SQLi via ajax.php Category paramA weakness has been identified in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /voting/ajax.php?action=save_category. This manipulation of the argument Category causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-86281 | Sep 07, 2026 |
CSRF in SourceCodester Syllabus-Aligned LMS 1.0A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This impacts an unknown function. Performing a manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-86280 | Sep 07, 2026 |
SourceCodester LMS 1.0: Remote Cleartext Sensitive Data via cict_portal.sqlA vulnerability was identified in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This affects an unknown function of the file cict_portal.sql. Such manipulation leads to cleartext storage of sensitive information. It is possible to launch the attack remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-86279 | Sep 07, 2026 |
SourceCodester SLA 1.0 Session Fixation via auth_process.php (CVE-2026-86279)A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The impacted element is an unknown function of the file auth_process.php of the component Login. This manipulation causes session fixiation. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-86278 | Sep 07, 2026 |
SourceCodester Syllabus-Aligned LMS 1.0 XSS via manage_subjects.phpA vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected element is an unknown function of the file manage_subjects.php. The manipulation of the argument msg/title/content results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used. |
|
| CVE-2026-86277 | Sep 07, 2026 |
SourceCodester Syllabus-Aligned LMS 1.0 Auth Bypass in delete_exam.php via IDA vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. Impacted is an unknown function of the file delete_exam.php. The manipulation of the argument ID leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-86276 | Sep 07, 2026 |
SourceCodester Syllabus-Aligned LMAES 1.0 HCC via db.php Remote ExecA flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been published and may be used. |
|
| CVE-2026-86275 | Sep 07, 2026 |
SourceCodester LMS 1.0 Privilege Escalation via Role ManipulationA vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This vulnerability affects the function register of the file auth.php. Performing a manipulation of the argument role results in improper privilege management. Remote exploitation of the attack is possible. The exploit is now public and may be used. |
|
| CVE-2026-86225 | Sep 06, 2026 |
SQLi in SourceCodester Class & Exam Timetabling Sys 1.0 via room_nameA vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The manipulation of the argument room_name leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. |
|