Sourcecodester Inventory Management System
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Sourcecodester Inventory Management System.
By the Year
In 2026 there have been 6 vulnerabilities in Sourcecodester Inventory Management System with an average score of 5.2 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 6 | 5.23 |
It may take a day or so for new Inventory Management System vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Sourcecodester Inventory Management System Security Vulnerabilities
Auth Bypass via ID in invoice.php of SourceCodester IMS 1.0
CVE-2026-90697
5.3 - Medium
- September 14, 2026
A vulnerability was identified in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file invoice.php. The manipulation of the argument ID leads to authorization bypass. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Insecure Direct Object Reference / IDOR
CVE-2026-90696: XSS in SC Inventory Mgt 1.0 (api/products_handler.php)
CVE-2026-90696
5.1 - Medium
- September 14, 2026
A vulnerability was determined in SourceCodester Inventory Management System 1.0. Affected by this issue is some unknown functionality of the file /api/products_handler.php of the component Product Management Module. Executing a manipulation of the argument Product_Name can lead to cross site scripting. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
XSS
SourceCodester Inventory Management System 1.0 XSS in Vendor Management API
CVE-2026-90695
5.1 - Medium
- September 14, 2026
A vulnerability was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /api/vendors_handler.php of the component Vendor Management. Performing a manipulation results in cross site scripting. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
XSS
SourceCodester Inventory 1.0 XSS in /api/customers_handler.php
CVE-2026-90694
5.1 - Medium
- September 14, 2026
A vulnerability has been found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file /api/customers_handler.php of the component Customer Management Module. Such manipulation of the argument Customer_Name leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
XSS
SourceCodester IMS 1.0: XSS via User Reg Endpoint
CVE-2026-13570
3.5 - Low
- June 29, 2026
A vulnerability was detected in SourceCodester Inventory Management System 1.0. Impacted is an unknown function of the file /api/users_handler.php of the component User Registration Endpoint. Performing a manipulation of the argument full_name results in cross site scripting. The attack is possible to be carried out remotely. The exploit is now public and may be used.
XSS
SourceCodester Inventory 1.0 Improper Access via Role in UsersHandler
CVE-2026-13568
7.3 - High
- June 29, 2026
A weakness has been identified in SourceCodester Inventory Management System 1.0. This vulnerability affects unknown code of the file /api/users_handler.php of the component User Registration Endpoint. This manipulation of the argument role causes improper access controls. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Authorization
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Sourcecodester Inventory Management System or by Sourcecodester? Click the Watch button to subscribe.