Sourcecodester
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Sourcecodester product.
RSS Feeds for Sourcecodester security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Sourcecodester products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Sourcecodester Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 271 vulnerabilities in Sourcecodester with an average score of 5.9 out of ten. Last year, in 2025 Sourcecodester had 132 security vulnerabilities published. That is, 139 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 0.46
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 271 | 5.88 |
| 2025 | 132 | 6.33 |
| 2024 | 15 | 6.27 |
| 2023 | 1 | 7.20 |
| 2022 | 2 | 9.80 |
| 2021 | 6 | 8.45 |
| 2020 | 0 | 0.00 |
| 2019 | 2 | 0.00 |
It may take a day or so for new Sourcecodester vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Sourcecodester Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-16486 | Jul 21, 2026 |
CVE-2026-16486 XSS in SRC Class/Exam Timetabling System 1.0 (BSIS.php)A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSIS.php. Performing a manipulation of the argument day results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used. |
|
| CVE-2026-16485 | Jul 21, 2026 |
XSS in SourceCodester Class and Exam Timetabling System 1.0 (/class.php)A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /class.php. Such manipulation of the argument day leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-16484 | Jul 21, 2026 |
A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_subjecta.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. |
|
| CVE-2026-16228 | Jul 19, 2026 |
SQLi in SRC Class & Exam Timetabling System 1.0 (edit_schoolyr.php)A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_schoolyr.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. |
|
| CVE-2026-16227 | Jul 19, 2026 |
SQLi in SourceCodester Class & Exam Timetabling 1.0 via edit_subject.php ID paramA security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /edit_subject.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-16226 | Jul 19, 2026 |
SourceCodester Pizzafy 1.0 Unrestricted Upload via admin_class_novo.phpA weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack is possible to be carried out remotely. |
|
| CVE-2026-16203 | Jul 19, 2026 |
SourceCodester Class & Exam Timetabling Sys 1.0 XSS via /forCYS.php (course param)A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /forCYS.php. Such manipulation of the argument course leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available and might be used. |
|
| CVE-2026-16202 | Jul 19, 2026 |
XSS in SourceCodester Class & Exam Timetabling System 1.0 via /CYS.phpA vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /CYS.php. This manipulation of the argument course causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-16156 | Jul 18, 2026 |
SourceCodester CEXTS 1.0 XSS via day param in forexam.phpA security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /forexam.php. The manipulation of the argument day results in cross site scripting. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-16155 | Jul 18, 2026 |
XSS in SourceCodester Class/Exam Timetabling System 1.0 via /schoolyr.php syA vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /schoolyr.php. The manipulation of the argument sy leads to cross site scripting. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-16154 | Jul 18, 2026 |
SQL Injection in SourceCodester C&E Timetabling System v1.0 /edit_room1.phpA vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerability is an unknown functionality of the file /edit_room1.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-16152 | Jul 18, 2026 |
SQL Injection in SourceCodester Class/Exam 1.0 /edit_rooma.phpA vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_rooma.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. |
|
| CVE-2026-15715 | Jul 14, 2026 |
XSS in /exam.php of SourceCodester Class & Exam Timetabling System 1.0A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /exam.php. Such manipulation of the argument day leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-15703 | Jul 14, 2026 |
SourceCodester Simple & Nice Shopping Cart 1.0 SQLi in userproductdeletequery.phpA vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unknown code of the file /admin/userproductdeletequery.php. Performing a manipulation of the argument user_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. |
|
| CVE-2026-15597 | Jul 13, 2026 |
SQLi in SourceCodester Exam Timetabling 1.0 via edit_exam2.phpA security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/2.php. This affects an unknown function of the file /edit_exam2.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-15596 | Jul 13, 2026 |
XSS in subject.php (sc) Class & Exam Timetabling System 1.0A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /subject.php. Such manipulation of the argument subject leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-15595 | Jul 13, 2026 |
XSS in SourceCodester Class & Exam Timetabling System 1.0 - /forsubject.phpA vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /forsubject.php. This manipulation of the argument subject causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-15540 | Jul 13, 2026 |
Imp File Include in SourceCodester Online Book Store 1.0 AdminA vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page results in improper control of filename for include/require statement in php program. It is possible to initiate the attack remotely. The exploit is now public and may be used. |
|
| CVE-2026-15539 | Jul 13, 2026 |
SourceCodester Online Book Store 1.0 Unrestricted Remote UploadA security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown function of the file /admin/index.php?page=books of the component Book Image Upload Feature. Such manipulation leads to unrestricted upload. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-15537 | Jul 13, 2026 |
SQLi in SourceCodester Online Book Store System 1.0 admin/login.phpA security flaw has been discovered in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file admin/login.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-15532 | Jul 13, 2026 |
CVE-2026-15532 XSS in SourceCodester Online Book Store Sys 1.0 User MGMT ModA vulnerability was identified in SourceCodester Online Book Store System 1.0. This issue affects some unknown processing of the component User Management Module. Such manipulation of the argument Name/Username leads to cross site scripting. The attack can be executed remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-15190 | Jul 09, 2026 |
SQL Injection in SourceCodester Shopping Cart Script 1.0 via /login.phpA vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown part of the file /login.php. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. |
|
| CVE-2026-14778 | Jul 05, 2026 |
Improper Auth in SourceCodester OnlineExam LMS 1.0 via /ajax_enroll.phpA security vulnerability has been detected in SourceCodester Onlne Examination & Learning Management System 1.0. This affects an unknown part of the file /ajax_enroll.php of the component Enrollment Management. The manipulation of the argument student_id/schedule_id/action leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The name of the affected product appears to have a typo in it. |
|
| CVE-2026-14777 | Jul 05, 2026 |
SourceCodester Onlne LMS 1.0 Unrestricted File Upload via /announcements.phpA weakness has been identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this issue is some unknown functionality of the file /announcements.php. Executing a manipulation can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The name of the affected product appears to have a typo in it. |
|
| CVE-2026-14776 | Jul 05, 2026 |
Unrestricted Upload via pathinfo in SourceCodester Onlne LMS 1.0 (FilenameExt)A security flaw has been discovered in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is the function pathinfo of the file /upload_files.php of the component Filename Extension. Performing a manipulation results in unrestricted upload. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The name of the affected product appears to have a typo in it. |
|
| CVE-2026-14775 | Jul 05, 2026 |
SourceCodester Exam LMS 1.0 - Unrestricted Upload (user_id)A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unknown function of the file /process_lesson.php. Such manipulation of the argument user_id leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the affected product appears to have a typo in it. |
|
| CVE-2026-14772 | Jul 05, 2026 |
SourceCodester Class Timetabling 1.0 PHP: Remote SQLi via ID in edit_course1.phpA vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0/1.php. The impacted element is an unknown function of the file /edit_course1.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-14771 | Jul 05, 2026 |
SQLi in SourceCodester Class & Exam Timetabling System 1.0 edit_exam1.phpA flaw has been found in SourceCodester Class and Exam Timetabling System 1.0/1.php. The affected element is an unknown function of the file /edit_exam1.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. |
|
| CVE-2026-14770 | Jul 05, 2026 |
SQLi in SourceCodester Class & Exam Timetabling 1.0 /edit_room.phpA vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /edit_room.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. |
|
| CVE-2026-14734 | Jul 05, 2026 |
SQLi in SourceCodester Class & Exam Timetabling System 1.0 via /edit_product.phpA flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /edit_product.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. |
|
| CVE-2026-14733 | Jul 05, 2026 |
SQLi ID in /edit_coursea.php, SourceCodester Class & Exam Timetabling System 1.0A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the file /edit_coursea.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now public and may be used. |
|
| CVE-2026-14732 | Jul 05, 2026 |
SQLi via ID in /edit_exam.php SourceCodester Class & Exam Timetabling Sys 1.0A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_exam.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-14725 | Jul 05, 2026 |
SourceCodester Online Boat Reservation System 1.0 Session Expiration Remote DoSA vulnerability was identified in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality. Such manipulation leads to session expiration. It is possible to launch the attack remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-14719 | Jul 05, 2026 |
SourceCodester Onlne Exam LMS 1.0 Remote Role Manipulation in register.phpA flaw has been found in SourceCodester Onlne Examination & Learning Management System 1.0. The impacted element is an unknown function of the file register.php of the component Registration Endpoint. Executing a manipulation of the argument role can lead to improper privilege management. The attack can be executed remotely. The exploit has been published and may be used. The name of the affected product appears to have a typo in it. |
|
| CVE-2026-14713 | Jul 05, 2026 |
SQLi in SourceCodester Pizzafy E-Commerce 1.0 admin ajax.php (confirm_order)A security flaw has been discovered in SourceCodester Pizzafy E-Commerce System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-14698 | Jul 05, 2026 |
SourceCodester Syllabus-LM 1.0 Unrestricted File Upload via upload_files.phpA security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management and Examination System 1.0. Impacted is an unknown function of the file upload_files.php. Performing a manipulation results in unrestricted upload. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. |
|
| CVE-2026-14695 | Jul 05, 2026 |
SQLi in SourceCodester Multi-Vendor Grocery Sys 1.0 Registration HandlerA vulnerability was found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This affects the function save_client of the file classes/Users.php of the component Registration Handler. The manipulation of the argument Name results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used. |
|
| CVE-2026-14694 | Jul 05, 2026 |
SQLi via POST cancel_order in SourceCodester Multi-Vendor Grocery 1.0A vulnerability has been found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. Affected by this issue is the function cancel_order of the file classes/Master.php of the component POST Parameter Handler. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. |
|
| CVE-2026-14693 | Jul 05, 2026 |
SourceCodester Multi-Vendor Grocery MS 1.0: Remote Imp. Auth via cancel_orderA flaw has been found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. Affected by this vulnerability is the function cancel_order of the file classes/Master.php. Executing a manipulation can lead to improper authorization. The attack may be performed from remote. The exploit has been published and may be used. |
|
| CVE-2026-14692 | Jul 05, 2026 |
SQLi in POST Parameter Handler SourceCodester MVOGMS 1.0 (5.7.26) RemoteA vulnerability was detected in SourceCodester Multi-Vendor Online Grocery Management System 1.0/5.7.26. Affected is the function save_shop_type of the file classes/Master.php of the component POST Parameter Handler. Performing a manipulation results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. |
|
| CVE-2026-14691 | Jul 05, 2026 |
Code Inject CVE-2026-14691 in SrcCodester Multi-Vendor Grocery Sys 1.0 SetHandlerA security vulnerability has been detected in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This impacts the function update_settings_info of the file classes/SystemSettings.php of the component Setting Handler. Such manipulation of the argument content[] leads to code injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-14690 | Jul 05, 2026 |
Improper Auth in SourceCodester Multi-Vendor Online Grocery Mgmt 1.0 via Users.phpA weakness has been identified in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This affects the function save_users of the file classes/Users.php. This manipulation causes improper authorization. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. |
|
| CVE-2026-14654 | Jul 04, 2026 |
SQLi in SourceCodester SCSS 1.0 /admin/girlsproductdeletequery.phpA vulnerability was identified in SourceCodester Simple and Nice Shopping Cart Script 1.0. Affected is an unknown function of the file /admin/girlsproductdeletequery.php. Such manipulation of the argument user_id leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-14653 | Jul 04, 2026 |
SQL Injection in SourceCodester Simple & Nice Cart 1.0 admin/mensproductdel.phpA vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /admin/mensproductdeletequery.php. This manipulation of the argument user_id causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-14652 | Jul 04, 2026 |
SQL Injection in SourceCodester Shopping Cart Script 1.0 AdminA vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown function of the file /admin/login.php of the component Admin Login. The manipulation of the argument Username results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. |
|
| CVE-2026-14642 | Jul 04, 2026 |
CVE-2026-14642: SQLi in edit_class2.php (Class & Exam Timetabling 1.0)A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /edit_class2.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. |
|
| CVE-2026-14641 | Jul 04, 2026 |
SQLi in Class and Exam Timetabling System 1.0: /edit_course.php ID paramA vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit_course.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. |
|
| CVE-2026-14609 | Jul 03, 2026 |
Session Fixation in SourceCodester CET Automated Grading 1.0A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue affects some unknown processing. The manipulation results in session fixiation. The attack can be executed remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit is now public and may be used. |
|
| CVE-2026-14608 | Jul 03, 2026 |
CET Automated Grading 1.0 POST Handler Auth Bypass via IDA security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=view_student of the component POST Handler. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. |
|
| CVE-2026-13571 | Jun 29, 2026 |
SourceCodester SFOS 1.0 cart.php Business Logic Error via item_priceA flaw has been found in SourceCodester Simple Food Ordering System 1.0. The affected element is an unknown function of the file /cart.php. Executing a manipulation of the argument item_price can lead to business logic errors. The attack may be performed from remote. The exploit has been published and may be used. |
|