Sourcecodester
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Sourcecodester product.
RSS Feeds for Sourcecodester security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Sourcecodester products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Sourcecodester Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 308 vulnerabilities in Sourcecodester with an average score of 5.9 out of ten. Last year, in 2025 Sourcecodester had 132 security vulnerabilities published. That is, 176 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.43
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 308 | 5.90 |
| 2025 | 132 | 6.33 |
| 2024 | 15 | 6.27 |
| 2023 | 1 | 7.20 |
| 2022 | 2 | 9.80 |
| 2021 | 6 | 8.45 |
| 2020 | 0 | 0.00 |
| 2019 | 2 | 0.00 |
It may take a day or so for new Sourcecodester vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Sourcecodester Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-77392 | Aug 21, 2026 |
Remote SQLi in SourceCodester Dynamic Input Field Generator 1.0 (saveUser)A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of the argument Researcher causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-77391 | Aug 21, 2026 |
CVE-2026-77391 XSRF in SourceCodester Dynamic Input Field Generator 1.0A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-76999 | Aug 20, 2026 |
SourceCodester Grading System 1.0 - Add Grade Improper AuthA vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be initiated remotely. |
|
| CVE-2026-76998 | Aug 20, 2026 |
SQLi in SourceCodester Simple Online Food Ordering 1.0 via /admin/ajax.phpA security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=delete_category. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-76997 | Aug 20, 2026 |
SQLi via /admin/ajax.php?id in SC SOFO 1.0A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=save_category. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-76996 | Aug 20, 2026 |
SQLi via ID in SourceCodester Food Order System 1.0A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/view_order.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-76995 | Aug 20, 2026 |
SourceCodester SOFOS 1.0 Unrestricted File Upload via admin/ajax.phpA vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_menu. The manipulation of the argument img leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-76050 | Aug 19, 2026 |
SQLi in SourceCodester SOFS 1.0 via /admin/ajax.php?action=delete_menuA vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?action=delete_menu. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. |
|
| CVE-2026-76049 | Aug 19, 2026 |
Simple Online Food Ordering System v1.0 SQLi via ID in admin/ajax.phpA vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=save_menu. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-76048 | Aug 19, 2026 |
Remote SQLi via ajax.php in SourceCodester Food Ordering 1.0A flaw has been found in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. |
|
| CVE-2026-75151 | Aug 18, 2026 |
CSRF in SourceCodester Online Examination & LMS 1.0A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. |
|
| CVE-2026-75080 | Aug 17, 2026 |
SourceCodester Class & Exam Timetabling 1.0 Remote SQLi via /edit_subject1.phpA security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the file /edit_subject1.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-75079 | Aug 17, 2026 |
SQLi in SourceCodester Timetabling 1.0 via ID in edit_subject2.phpA weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_subject2.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-75078 | Aug 17, 2026 |
XSS in SourceCodester Class & Exam Timetabling Sys 1.0 via BSHRM1.phpA security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSHRM1.php. Performing a manipulation of the argument course results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-75077 | Aug 17, 2026 |
XSS via /BSCE2.php in SourceCodester Class and Exam Timetabling System 1.0A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /BSCE2.php. Such manipulation of the argument course leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-75014 | Aug 17, 2026 |
SQLi in SourceCodester Pet Grooming Mgmt Software 1.0 get_barcode_data.phpA flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/get_barcode_data.php. This manipulation of the argument barcode causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. |
|
| CVE-2026-19987 | Aug 17, 2026 |
CVE-2026-19987: Directory Listing in SC Best Employee Management System 1.0A security vulnerability has been detected in SourceCodester Best Employee Management System 1.0. This affects an unknown function of the file /assets/uploadImage/Profile/. Such manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely. |
|
| CVE-2026-19925 | Aug 16, 2026 |
SQLi in SourceCodester Stock Management System 1.0 delete_supplierA vulnerability was detected in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /classes/Master.php?f=delete_supplier. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used. |
|
| CVE-2026-19904 | Aug 15, 2026 |
XSS in SourceCodester Online Book Store 1.0 Admin Site SettingsA vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file /admin/index.php?page=site_settings of the component System Settings Module. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit has been made public and could be used. |
|
| CVE-2026-19903 | Aug 15, 2026 |
SourceCodester Online Clothing Store 1.0 SQL Backup Path DisclosureA vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db/shopping.sql of the component SQL Database Backup. The manipulation leads to files or directories accessible. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-19899 | Aug 15, 2026 |
SQLi in SourceCodester Class & Exam Timetabling System 1.0 /edit_teacher.phpA vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /edit_teacher.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-19839 | Aug 14, 2026 |
Unrestricted File Upload CVE-2026-19839 in Simple Doctors App 1.0A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue affects the function save_doctor of the file /save_file.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit is now public and may be used. |
|
| CVE-2026-19825 | Aug 14, 2026 |
SourceCodester SCM 1.0: Remote SQLi via save_serviceA security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_service. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-19787 | Aug 14, 2026 |
SQL Injection via ID in Air Cargo Mgmt Sys 1.0A vulnerability was determined in SourceCodester Air Cargo Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_cargo_type. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-19710 | Aug 13, 2026 |
Remote SQLi in SourceCodester Simple Student Info SysA vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown functionality of the file app/admin/departments/view_department.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. |
|
| CVE-2026-19384 | Aug 10, 2026 |
SQLi via ID in /admin/ajax.php?action=set_appointment - Simple Doctors App 1.0A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointment. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-19231 | Aug 07, 2026 |
SQLi in SC Simple Doctors Appointment 1.0 via delete_appointmentA security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=delete_appointment. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-19230 | Aug 07, 2026 |
XSS in SourceCodester Photo Share 1.0 Comment Input Box via /social/ajax.phpA vulnerability was identified in SourceCodester Photo Share Website 1.0. This affects an unknown part of the file /social/ajax.php?action=save_upload of the component Comment Input Box. The manipulation of the argument content leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-19229 | Aug 07, 2026 |
SourceCodester Online Clothing Store: Dreamweaver Metadata /_notes/ Info DisclosureA vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functionality of the file /_notes/ of the component Dreamweaver Metadata Files. Executing a manipulation can lead to file and directory information exposure. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-19211 | Aug 07, 2026 |
SQLi in SourceCodester Photo Share Website 1.0 via ajax.phpA vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /social/ajax.php?action=signup. Performing a manipulation of the argument email results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. |
|
| CVE-2026-19210 | Aug 07, 2026 |
SourceCodester PhotoShare 1.0 - Unrestricted Upload via ajax.php img[]A vulnerability has been found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the file /social/ajax.php?action=save_upload. Such manipulation of the argument img[]/imgName[] leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-19209 | Aug 07, 2026 |
CVE-2026-19209 XSS in SourceCodester Photo Share 1.0 via Comment paramA flaw has been found in SourceCodester Photo Share Website 1.0. The affected element is an unknown function of the file /social/index.php?page=home. This manipulation of the argument Comment causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. |
|
| CVE-2026-19196 | Aug 07, 2026 |
SQLi in SourceCodester Photo Share Website 1.0 via ajax.phpA vulnerability was found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the file /social/ajax.php?action=login. The manipulation of the argument email results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. |
|
| CVE-2026-19066 | Aug 06, 2026 |
OELMS 1.0 Auth Bypass via class_group in view_students.phpA vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unknown function of the file view_students.php. Such manipulation of the argument class_group leads to authorization bypass. The attack may be launched remotely. |
|
| CVE-2026-19065 | Aug 06, 2026 |
Unrestricted Upload in SC Online Exam & LMS 1.0 (upload_files.php)A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects some unknown processing of the file upload_files.php. This manipulation causes unrestricted upload. The attack may be initiated remotely. |
|
| CVE-2026-19064 | Aug 06, 2026 |
SourceCodester OELMS 1.0 /view.php ID Manip Bypasses Auth RemotelyA vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affects unknown code of the file /view.php. The manipulation of the argument ID results in authorization bypass. The attack can be launched remotely. |
|
| CVE-2026-19021 | Aug 06, 2026 |
SQLi in SourceCodester CRM 1.0 via delete_product endpointA security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=delete_product. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-16486 | Jul 21, 2026 |
CVE-2026-16486 XSS in SRC Class/Exam Timetabling System 1.0 (BSIS.php)A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSIS.php. Performing a manipulation of the argument day results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used. |
|
| CVE-2026-16485 | Jul 21, 2026 |
XSS in SourceCodester Class and Exam Timetabling System 1.0 (/class.php)A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /class.php. Such manipulation of the argument day leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-16484 | Jul 21, 2026 |
Remote SQL Injection in /edit_subjecta.php of Class & Exam Timetabling Sys 1.0A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_subjecta.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. |
|
| CVE-2026-16228 | Jul 19, 2026 |
SQLi in SRC Class & Exam Timetabling System 1.0 (edit_schoolyr.php)A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_schoolyr.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. |
|
| CVE-2026-16227 | Jul 19, 2026 |
SQLi in SourceCodester Class & Exam Timetabling 1.0 via edit_subject.php ID paramA security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /edit_subject.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-16226 | Jul 19, 2026 |
SourceCodester Pizzafy 1.0 Unrestricted Upload via admin_class_novo.phpA weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack is possible to be carried out remotely. |
|
| CVE-2026-16203 | Jul 19, 2026 |
SourceCodester Class & Exam Timetabling Sys 1.0 XSS via /forCYS.php (course param)A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /forCYS.php. Such manipulation of the argument course leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available and might be used. |
|
| CVE-2026-16202 | Jul 19, 2026 |
XSS in SourceCodester Class & Exam Timetabling System 1.0 via /CYS.phpA vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /CYS.php. This manipulation of the argument course causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-16156 | Jul 18, 2026 |
SourceCodester CEXTS 1.0 XSS via day param in forexam.phpA security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /forexam.php. The manipulation of the argument day results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-16155 | Jul 18, 2026 |
XSS in SourceCodester Class/Exam Timetabling System 1.0 via /schoolyr.php syA vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /schoolyr.php. The manipulation of the argument sy leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-16154 | Jul 18, 2026 |
SQL Injection in SourceCodester C&E Timetabling System v1.0 /edit_room1.phpA vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerability is an unknown functionality of the file /edit_room1.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-16152 | Jul 18, 2026 |
SQL Injection in SourceCodester Class/Exam 1.0 /edit_rooma.phpA vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_rooma.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. |
|
| CVE-2026-15715 | Jul 14, 2026 |
XSS in /exam.php of SourceCodester Class & Exam Timetabling System 1.0A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /exam.php. Such manipulation of the argument day leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used. |
|