Sourcecodester
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Sourcecodester product.
RSS Feeds for Sourcecodester security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Sourcecodester products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Sourcecodester Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 346 vulnerabilities in Sourcecodester with an average score of 6.0 out of ten. Last year, in 2025 Sourcecodester had 132 security vulnerabilities published. That is, 214 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.37
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 346 | 5.97 |
| 2025 | 132 | 6.33 |
| 2024 | 15 | 6.27 |
| 2023 | 1 | 7.20 |
| 2022 | 2 | 9.80 |
| 2021 | 6 | 8.45 |
| 2020 | 0 | 0.00 |
| 2019 | 2 | 0.00 |
It may take a day or so for new Sourcecodester vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Sourcecodester Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-86298 | Sep 07, 2026 |
SQLi in SourceCodester Class & Exam Timetabling 1.0 via delete_subject.phpA security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /delete_subject.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-86294 | Sep 07, 2026 |
SourceCodester Simple Traffic Offense System 1.0 XSS via site_name/site_descA vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of the component Settings Update Endpoint. The manipulation of the argument site_name/site_desc leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-86293 | Sep 07, 2026 |
Auth Bypass via ID Manipulation in Traffic Offense System 1.0 Deletion EndpointA flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is an unknown functionality of the file delete-user.php of the component Deletion Endpoint. Executing a manipulation of the argument ID can lead to missing authentication. The attack may be launched remotely. The exploit has been published and may be used. |
|
| CVE-2026-86292 | Sep 07, 2026 |
Missing Auth in SCTOS 1.0 via saveuser.php Remote (Public Exploit)A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0. Affected is an unknown function of the file saveuser.php of the component User Creation. Performing a manipulation of the argument position results in missing authentication. The attack may be initiated remotely. The exploit is now public and may be used. |
|
| CVE-2026-86290 | Sep 07, 2026 |
SourceCodester Online Voting 1.0 SQLi via ajax.php Category paramA weakness has been identified in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /voting/ajax.php?action=save_category. This manipulation of the argument Category causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-86281 | Sep 07, 2026 |
CSRF in SourceCodester Syllabus-Aligned LMS 1.0A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This impacts an unknown function. Performing a manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-86280 | Sep 07, 2026 |
SourceCodester LMS 1.0: Remote Cleartext Sensitive Data via cict_portal.sqlA vulnerability was identified in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This affects an unknown function of the file cict_portal.sql. Such manipulation leads to cleartext storage of sensitive information. It is possible to launch the attack remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-86279 | Sep 07, 2026 |
SourceCodester SLA 1.0 Session Fixation via auth_process.php (CVE-2026-86279)A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The impacted element is an unknown function of the file auth_process.php of the component Login. This manipulation causes session fixiation. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-86278 | Sep 07, 2026 |
SourceCodester Syllabus-Aligned LMS 1.0 XSS via manage_subjects.phpA vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected element is an unknown function of the file manage_subjects.php. The manipulation of the argument msg/title/content results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used. |
|
| CVE-2026-86277 | Sep 07, 2026 |
SourceCodester Syllabus-Aligned LMS 1.0 Auth Bypass in delete_exam.php via IDA vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. Impacted is an unknown function of the file delete_exam.php. The manipulation of the argument ID leads to authorization bypass. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-86276 | Sep 07, 2026 |
SourceCodester Syllabus-Aligned LMAES 1.0 HCC via db.php Remote ExecA flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been published and may be used. |
|
| CVE-2026-86275 | Sep 07, 2026 |
SourceCodester LMS 1.0 Privilege Escalation via Role ManipulationA vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This vulnerability affects the function register of the file auth.php. Performing a manipulation of the argument role results in improper privilege management. Remote exploitation of the attack is possible. The exploit is now public and may be used. |
|
| CVE-2026-86225 | Sep 06, 2026 |
SQLi in SourceCodester Class & Exam Timetabling Sys 1.0 via room_nameA vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The manipulation of the argument room_name leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-86224 | Sep 06, 2026 |
SourceCodester Class & Exam Timetabling Sys 1.0 SQLi via mysqli_queryA vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a manipulation of the argument fname can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-86223 | Sep 06, 2026 |
SQLi in SourceCodester Class & Exam Timetabling System 1.0 via mysqli_queryA vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of the file /admin/modal_add_coursea.php. Performing a manipulation of the argument course results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. |
|
| CVE-2026-86222 | Sep 06, 2026 |
SQLi in SourceCodester Class & Exam Timetabling System 1.0 via mysqli_queryA vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. This affects the function mysqli_query of the file /admin/modal_add_course2.php. Such manipulation of the argument course leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-86221 | Sep 06, 2026 |
SourceCodester Class & Exam Timetabling System 1.0 SQLi via mysqli_queryA flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is the function mysqli_query of the file /admin/modal_add_course1.php. This manipulation of the argument course causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. |
|
| CVE-2026-86220 | Sep 06, 2026 |
SQL Injection in SourceCodester CET System 1.0 via mysqli_queryA vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. The affected element is the function mysqli_query of the file /admin/modal_add_course.php. The manipulation of the argument course results in sql injection. The attack can be launched remotely. The exploit is now public and may be used. |
|
| CVE-2026-86210 | Sep 06, 2026 |
SQLi in SCCSETS 1.0 via /delete_user_account.phpA security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_user_account.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-86209 | Sep 06, 2026 |
SourceCodester 1.0 SQLi via delete_user.phpA weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_user.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-86208 | Sep 06, 2026 |
SourceCodester Class & Exam Timetabling 1.0 SQLi via /delete_teacher.phpA security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-86162 | Sep 06, 2026 |
SQLi via Username in SourceCodester Online Voting System 1.0 loginA vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-86161 | Sep 06, 2026 |
SourceCodester Online Voting System 1.0 SQLi via /ajax.php?action=delete_categoryA vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. |
|
| CVE-2026-86160 | Sep 06, 2026 |
SourceCodester Online Voting System 1.0 SQLi via /ajax.php delete_voting IDA vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-86159 | Sep 06, 2026 |
SourceCodester OV System 1.0 SQLI via ID in ajax.phpA flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. |
|
| CVE-2026-85512 | Sep 04, 2026 |
Missing Auth in SourceCodester Class & Exam Timetabling 1.0 (admin/session.php)A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The manipulation of the argument ID results in missing authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-82554 | Aug 30, 2026 |
SourceCodester QueueMS 1.0 - XSS in /api/add_customer.phpA flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part of the file /api/add_customer.php. This manipulation of the argument Name causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. |
|
| CVE-2026-81203 | Aug 26, 2026 |
SQLi via email param in SourceCodester SOFS 1.0 /admin/ajax.phpA vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-78248 | Aug 24, 2026 |
SQLi Remote via ajax.php in SourceCodester Simple Online Food Ordering System 1.0A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/ajax.php?action=save_settings. This manipulation of the argument Name causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-78247 | Aug 24, 2026 |
SQL Injection in SourceCodester Simple Online Food Ordering System 1.0 via ajax.phpA vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. |
|
| CVE-2026-78199 | Aug 24, 2026 |
SQLi in sourcecodester Food Ordering 1.0 via view_prod.php IDA vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/view_prod.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. |
|
| CVE-2026-78198 | Aug 24, 2026 |
SQLi in SourceCodester SOFOS 1.0 via add_to_cart actionA security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=add_to_cart. Such manipulation of the argument pid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-78197 | Aug 24, 2026 |
SQLi in SC Simple Online Food Ordering System 1.0 via ajax.php UsernameA weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /fos/admin/ajax.php?action=save_user. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-78115 | Aug 23, 2026 |
IMPAIRED AUTH in SourceCodester C&E Timetabling System via edit_user_account.phpA vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /admin/edit_user_account.php of the component User Account Update. Such manipulation of the argument id/username leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-78060 | Aug 23, 2026 |
CVE-2026-78060: XSS via getOrderReport.php in SourceCodester Stock Mgmt 1.0A vulnerability was found in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /php_action/getOrderReport.php. Performing a manipulation of the argument clientName/clientContact results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. |
|
| CVE-2026-78059 | Aug 23, 2026 |
SourceCodester Stock Management 1.0 XSS via /php_action/printOrder.phpA vulnerability has been found in SourceCodester Stock Management System 1.0. This vulnerability affects unknown code of the file /php_action/printOrder.php. Such manipulation of the argument clientName/clientContact leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-78055 | Aug 23, 2026 |
CVE-2026-78055: XSS in SourceCodester Class & Exam Timetabling Sys 1.0A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /BSIT2.php. The manipulation of the argument course leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-78054 | Aug 23, 2026 |
SourceCodester Class & Exam Timetabling System 1.0 XSS via /BSIS1.phpA weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /BSIS1.php. Executing a manipulation of the argument course can lead to cross site scripting. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-77392 | Aug 21, 2026 |
Remote SQLi in SourceCodester Dynamic Input Field Generator 1.0 (saveUser)A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of the argument Researcher causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-77391 | Aug 21, 2026 |
CVE-2026-77391 XSRF in SourceCodester Dynamic Input Field Generator 1.0A security flaw has been discovered in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This affects an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-76999 | Aug 20, 2026 |
SourceCodester Grading System 1.0 - Add Grade Improper AuthA vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be initiated remotely. |
|
| CVE-2026-76998 | Aug 20, 2026 |
SQLi in SourceCodester Simple Online Food Ordering 1.0 via /admin/ajax.phpA security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=delete_category. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-76997 | Aug 20, 2026 |
SQLi via /admin/ajax.php?id in SC SOFO 1.0A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=save_category. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-76996 | Aug 20, 2026 |
SQLi via ID in SourceCodester Food Order System 1.0A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/view_order.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-76995 | Aug 20, 2026 |
SourceCodester SOFOS 1.0 Unrestricted File Upload via admin/ajax.phpA vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_menu. The manipulation of the argument img leads to unrestricted upload. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-76050 | Aug 19, 2026 |
SQLi in SourceCodester SOFS 1.0 via /admin/ajax.php?action=delete_menuA vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This impacts an unknown function of the file /admin/ajax.php?action=delete_menu. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. |
|
| CVE-2026-76049 | Aug 19, 2026 |
Simple Online Food Ordering System v1.0 SQLi via ID in admin/ajax.phpA vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=save_menu. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-76048 | Aug 19, 2026 |
Remote SQLi via ajax.php in SourceCodester Food Ordering 1.0A flaw has been found in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=login. Executing a manipulation of the argument Username can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used. |
|
| CVE-2026-75151 | Aug 18, 2026 |
CSRF in SourceCodester Online Examination & LMS 1.0A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. |
|
| CVE-2026-75080 | Aug 17, 2026 |
SourceCodester Class & Exam Timetabling 1.0 Remote SQLi via /edit_subject1.phpA security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the file /edit_subject1.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. |
|