Sourcecodester Sourcecodester

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Sourcecodester product.

RSS Feeds for Sourcecodester security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Sourcecodester products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Sourcecodester Sorted by Most Security Vulnerabilities since 2018

By the Year

In 2026 there have been 308 vulnerabilities in Sourcecodester with an average score of 5.9 out of ten. Last year, in 2025 Sourcecodester had 132 security vulnerabilities published. That is, 176 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.43




Year Vulnerabilities Average Score
2026 308 5.90
2025 132 6.33
2024 15 6.27
2023 1 7.20
2022 2 9.80
2021 6 8.45
2020 0 0.00
2019 2 0.00

It may take a day or so for new Sourcecodester vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Sourcecodester Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-77392 Aug 21, 2026
Remote SQLi in SourceCodester Dynamic Input Field Generator 1.0 (saveUser) A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of the argument Researcher causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Dynamic Input Field Generator Using Html Css Php
CVE-2026-77391 Aug 21, 2026
CVE-2026-77391 XSRF in SourceCodester Dynamic Input Field Generator 1.0 A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Dynamic Input Field Generator Using Html Css Php
CVE-2026-76999 Aug 20, 2026
SourceCodester Grading System 1.0 - Add Grade Improper Auth A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be initiated remotely.
Cet Automated Grading System With Ai Predictive Analytics
CVE-2026-76998 Aug 20, 2026
SQLi in SourceCodester Simple Online Food Ordering 1.0 via /admin/ajax.php A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=delete_category. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Simple Online Food Ordering System
CVE-2026-76997 Aug 20, 2026
SQLi via /admin/ajax.php?id in SC SOFO 1.0 A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=save_category. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.
Simple Online Food Ordering System
CVE-2026-76996 Aug 20, 2026
SQLi via ID in SourceCodester Food Order System 1.0 A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/view_order.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
Simple Online Food Ordering System
CVE-2026-76995 Aug 20, 2026
SourceCodester SOFOS 1.0 Unrestricted File Upload via admin/ajax.php A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_menu. The manipulation of the argument img leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
Simple Online Food Ordering System
CVE-2026-76050 Aug 19, 2026
SQLi in SourceCodester SOFS 1.0 via /admin/ajax.php?action=delete_menu A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?action=delete_menu. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Simple Online Food Ordering System
CVE-2026-76049 Aug 19, 2026
Simple Online Food Ordering System v1.0 SQLi via ID in admin/ajax.php A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=save_menu. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Simple Online Food Ordering System
CVE-2026-76048 Aug 19, 2026
Remote SQLi via ajax.php in SourceCodester Food Ordering 1.0 A flaw has been found in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.
Simple Online Food Ordering System
CVE-2026-75151 Aug 18, 2026
CSRF in SourceCodester Online Examination & LMS 1.0 A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be initiated remotely.
Onlne Examination Learning Management System
CVE-2026-75080 Aug 17, 2026
SourceCodester Class & Exam Timetabling 1.0 Remote SQLi via /edit_subject1.php A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the file /edit_subject1.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
Class Exam Timetabling System
CVE-2026-75079 Aug 17, 2026
SQLi in SourceCodester Timetabling 1.0 via ID in edit_subject2.php A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_subject2.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
Class Exam Timetabling System
CVE-2026-75078 Aug 17, 2026
XSS in SourceCodester Class & Exam Timetabling Sys 1.0 via BSHRM1.php A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSHRM1.php. Performing a manipulation of the argument course results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
Class Exam Timetabling System
CVE-2026-75077 Aug 17, 2026
XSS via /BSCE2.php in SourceCodester Class and Exam Timetabling System 1.0 A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /BSCE2.php. Such manipulation of the argument course leads to cross site scripting. The attack may be launched remotely. The exploit is publicly available and might be used.
Class Exam Timetabling System
CVE-2026-75014 Aug 17, 2026
SQLi in SourceCodester Pet Grooming Mgmt Software 1.0 get_barcode_data.php A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/get_barcode_data.php. This manipulation of the argument barcode causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
Pet Grooming Management Software
CVE-2026-19987 Aug 17, 2026
CVE-2026-19987: Directory Listing in SC Best Employee Management System 1.0 A security vulnerability has been detected in SourceCodester Best Employee Management System 1.0. This affects an unknown function of the file /assets/uploadImage/Profile/. Such manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely.
Best Employee Management System
CVE-2026-19925 Aug 16, 2026
SQLi in SourceCodester Stock Management System 1.0 delete_supplier A vulnerability was detected in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /classes/Master.php?f=delete_supplier. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
Stock Management System
CVE-2026-19904 Aug 15, 2026
XSS in SourceCodester Online Book Store 1.0 Admin Site Settings A vulnerability was found in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file /admin/index.php?page=site_settings of the component System Settings Module. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit has been made public and could be used.
Online Book Store System
CVE-2026-19903 Aug 15, 2026
SourceCodester Online Clothing Store 1.0 SQL Backup Path Disclosure A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db/shopping.sql of the component SQL Database Backup. The manipulation leads to files or directories accessible. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Online Clothing Store
CVE-2026-19899 Aug 15, 2026
SQLi in SourceCodester Class & Exam Timetabling System 1.0 /edit_teacher.php A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /edit_teacher.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Class Exam Timetabling System
CVE-2026-19839 Aug 14, 2026
Unrestricted File Upload CVE-2026-19839 in Simple Doctors App 1.0 A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue affects the function save_doctor of the file /save_file.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit is now public and may be used.
Simple Doctors Appointment System
CVE-2026-19825 Aug 14, 2026
SourceCodester SCM 1.0: Remote SQLi via save_service A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_service. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
Simple Client Management System
CVE-2026-19787 Aug 14, 2026
SQL Injection via ID in Air Cargo Mgmt Sys 1.0 A vulnerability was determined in SourceCodester Air Cargo Management System 1.0. Impacted is an unknown function of the file /classes/Master.php?f=save_cargo_type. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Air Cargo Management System
CVE-2026-19710 Aug 13, 2026
Remote SQLi in SourceCodester Simple Student Info Sys A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown functionality of the file app/admin/departments/view_department.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Simple Student Information System
CVE-2026-19384 Aug 10, 2026
SQLi via ID in /admin/ajax.php?action=set_appointment - Simple Doctors App 1.0 A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointment. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Simple Doctors Appointment System
CVE-2026-19231 Aug 07, 2026
SQLi in SC Simple Doctors Appointment 1.0 via delete_appointment A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=delete_appointment. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
Simple Doctors Appointment System
CVE-2026-19230 Aug 07, 2026
XSS in SourceCodester Photo Share 1.0 Comment Input Box via /social/ajax.php A vulnerability was identified in SourceCodester Photo Share Website 1.0. This affects an unknown part of the file /social/ajax.php?action=save_upload of the component Comment Input Box. The manipulation of the argument content leads to cross site scripting. The attack may be initiated remotely. The exploit is publicly available and might be used.
Photo Share Website
CVE-2026-19229 Aug 07, 2026
SourceCodester Online Clothing Store: Dreamweaver Metadata /_notes/ Info Disclosure A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functionality of the file /_notes/ of the component Dreamweaver Metadata Files. Executing a manipulation can lead to file and directory information exposure. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Online Clothing Store
CVE-2026-19211 Aug 07, 2026
SQLi in SourceCodester Photo Share Website 1.0 via ajax.php A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /social/ajax.php?action=signup. Performing a manipulation of the argument email results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Photo Share Website
CVE-2026-19210 Aug 07, 2026
SourceCodester PhotoShare 1.0 - Unrestricted Upload via ajax.php img[] A vulnerability has been found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the file /social/ajax.php?action=save_upload. Such manipulation of the argument img[]/imgName[] leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Photo Share Website
CVE-2026-19209 Aug 07, 2026
CVE-2026-19209 XSS in SourceCodester Photo Share 1.0 via Comment param A flaw has been found in SourceCodester Photo Share Website 1.0. The affected element is an unknown function of the file /social/index.php?page=home. This manipulation of the argument Comment causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used.
Photo Share Website
CVE-2026-19196 Aug 07, 2026
SQLi in SourceCodester Photo Share Website 1.0 via ajax.php A vulnerability was found in SourceCodester Photo Share Website 1.0. The impacted element is an unknown function of the file /social/ajax.php?action=login. The manipulation of the argument email results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
Photo Share Website
CVE-2026-19066 Aug 06, 2026
OELMS 1.0 Auth Bypass via class_group in view_students.php A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unknown function of the file view_students.php. Such manipulation of the argument class_group leads to authorization bypass. The attack may be launched remotely.
Online Examination Learning Management System
CVE-2026-19065 Aug 06, 2026
Unrestricted Upload in SC Online Exam & LMS 1.0 (upload_files.php) A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects some unknown processing of the file upload_files.php. This manipulation causes unrestricted upload. The attack may be initiated remotely.
Online Examination Learning Management System
CVE-2026-19064 Aug 06, 2026
SourceCodester OELMS 1.0 /view.php ID Manip Bypasses Auth Remotely A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affects unknown code of the file /view.php. The manipulation of the argument ID results in authorization bypass. The attack can be launched remotely.
Online Examination Learning Management System
CVE-2026-19021 Aug 06, 2026
SQLi in SourceCodester CRM 1.0 via delete_product endpoint A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. Affected by this issue is some unknown functionality of the file /classes/Master.php?f=delete_product. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Computer Repair Shop Management System
CVE-2026-16486 Jul 21, 2026
CVE-2026-16486 XSS in SRC Class/Exam Timetabling System 1.0 (BSIS.php) A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSIS.php. Performing a manipulation of the argument day results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used.
Class Exam Timetabling System
CVE-2026-16485 Jul 21, 2026
XSS in SourceCodester Class and Exam Timetabling System 1.0 (/class.php) A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /class.php. Such manipulation of the argument day leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Class Exam Timetabling System
CVE-2026-16484 Jul 21, 2026
Remote SQL Injection in /edit_subjecta.php of Class & Exam Timetabling Sys 1.0 A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_subjecta.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
Class Exam Timetabling System
CVE-2026-16228 Jul 19, 2026
SQLi in SRC Class & Exam Timetabling System 1.0 (edit_schoolyr.php) A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_schoolyr.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Class Exam Timetabling System
CVE-2026-16227 Jul 19, 2026
SQLi in SourceCodester Class & Exam Timetabling 1.0 via edit_subject.php ID param A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /edit_subject.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Class Exam Timetabling System
CVE-2026-16226 Jul 19, 2026
SourceCodester Pizzafy 1.0 Unrestricted Upload via admin_class_novo.php A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack is possible to be carried out remotely.
Pizzafy Ecommerce System
CVE-2026-16203 Jul 19, 2026
SourceCodester Class & Exam Timetabling Sys 1.0 XSS via /forCYS.php (course param) A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /forCYS.php. Such manipulation of the argument course leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available and might be used.
Class Exam Timetabling System
CVE-2026-16202 Jul 19, 2026
XSS in SourceCodester Class & Exam Timetabling System 1.0 via /CYS.php A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /CYS.php. This manipulation of the argument course causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Class Exam Timetabling System
CVE-2026-16156 Jul 18, 2026
SourceCodester CEXTS 1.0 XSS via day param in forexam.php A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /forexam.php. The manipulation of the argument day results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
Class Exam Timetabling System
CVE-2026-16155 Jul 18, 2026
XSS in SourceCodester Class/Exam Timetabling System 1.0 via /schoolyr.php sy A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /schoolyr.php. The manipulation of the argument sy leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Class Exam Timetabling System
CVE-2026-16154 Jul 18, 2026
SQL Injection in SourceCodester C&E Timetabling System v1.0 /edit_room1.php A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerability is an unknown functionality of the file /edit_room1.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Class Exam Timetabling System
CVE-2026-16152 Jul 18, 2026
SQL Injection in SourceCodester Class/Exam 1.0 /edit_rooma.php A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_rooma.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Class Exam Timetabling System
CVE-2026-15715 Jul 14, 2026
XSS in /exam.php of SourceCodester Class & Exam Timetabling System 1.0 A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /exam.php. Such manipulation of the argument day leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Class Exam Timetabling System
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.