SourceCodester records
12 published records for vendor sourcecodester.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-28303No exploit | Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter at /admin/reports/iCWE-89 | Critical9.8 | — | 0.5% | Mar 19, 2024 |
36Monitor | CVE-2019-18417No exploit | Sourcecodester Restaurant Management System 1.0 allows an authenticated attacker to upload arbitrary files that can result in code executionsourcecodester · restaurant management system · CWE-434 | High8.8 | — | 1.7% | Oct 24, 2019 |
36Monitor | CVE-2024-33294No exploit | An issue in Library System using PHP/MySQli with Source Code V1.0 allows a remote attacker to execute arbitrary code via the _FAILE variableCWE-94 | Critical9.1 | — | 0.7% | May 6, 2024 |
35Monitor | CVE-2019-18414No exploit | Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulnerability due to a lacsourcecodester · restaurant management system · CWE-352 | High8.8 | — | 0.5% | Oct 24, 2019 |
29Monitor | CVE-2024-33306No exploit | SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" parameter in Create User.sourcecodester · laboratory management system · CWE-79 | High7.4 | — | 0.7% | May 1, 2024 |
28Monitor | CVE-2024-34231No exploit | A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scrsourcecodester · laboratory management system · CWE-79 | High7.1 | — | 0.5% | May 14, 2024 |
25Monitor | CVE-2024-51430Proof of concept | Cross Site Scripting vulnerability in online diagnostic lab management system using php v.1.0 allows a remote attacker to execute arbitrary CWE-79 | Medium6.4 | — | 0.6% | Oct 31, 2024 |
24Monitor | CVE-2021-41728No exploit | Cross Site Scripting (XSS) vulnerability exists in Sourcecodester News247 CMS 1.0 via the search function in articles.sourcecodester · news247 cms · CWE-79 | Medium6.1 | — | 0.6% | Oct 28, 2021 |
24Monitor | CVE-2024-34230No exploit | A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scrsourcecodester · laboratory management system · CWE-79 | Medium6.1 | — | 0.5% | May 14, 2024 |
24Monitor | CVE-2024-33305No exploit | SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Middle Name" parameter in Create User.sourcecodester · laboratory management system · CWE-79 | Medium6.1 | — | 0.4% | May 2, 2024 |
22Monitor | CVE-2025-6160No exploit | SourceCodester Client Database Management System user_customer_create_order.php sql injectionsourcecodester · downloading client database management system · CWE-74 | Medium5.5 | — | 0.6% | Jun 17, 2025 |
21Monitor | CVE-2024-33307No exploit | SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" parameter in Create User.sourcecodester · laboratory management system · CWE-79 | Medium5.4 | — | 0.4% | May 1, 2024 |
- CVE-2024-2830339Monitor
Open Source Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the date parameter at /admin/reports/i
CriticalCVSS 9.8No exploitEPSS 1%Mar 19, 2024
- CVE-2019-1841736Monitor
Sourcecodester Restaurant Management System 1.0 allows an authenticated attacker to upload arbitrary files that can result in code execution
HighCVSS 8.8No exploitEPSS 2%sourcecodester · restaurant management systemOct 24, 2019
- CVE-2024-3329436Monitor
An issue in Library System using PHP/MySQli with Source Code V1.0 allows a remote attacker to execute arbitrary code via the _FAILE variable
CriticalCVSS 9.1No exploitEPSS 1%May 6, 2024
- CVE-2019-1841435Monitor
Sourcecodester Restaurant Management System 1.0 is affected by an admin/staff-exec.php Cross Site Request Forgery vulnerability due to a lac
HighCVSS 8.8No exploitEPSS 0%sourcecodester · restaurant management systemOct 24, 2019
- CVE-2024-3330629Monitor
SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" parameter in Create User.
HighCVSS 7.4No exploitEPSS 1%sourcecodester · laboratory management systemMay 1, 2024
- CVE-2024-3423128Monitor
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scr
HighCVSS 7.1No exploitEPSS 0%sourcecodester · laboratory management systemMay 14, 2024
- CVE-2024-5143025Monitor
Cross Site Scripting vulnerability in online diagnostic lab management system using php v.1.0 allows a remote attacker to execute arbitrary
MediumCVSS 6.4Proof of conceptEPSS 1%Oct 31, 2024
- CVE-2021-4172824Monitor
Cross Site Scripting (XSS) vulnerability exists in Sourcecodester News247 CMS 1.0 via the search function in articles.
MediumCVSS 6.1No exploitEPSS 1%sourcecodester · news247 cmsOct 28, 2021
- CVE-2024-3423024Monitor
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scr
MediumCVSS 6.1No exploitEPSS 0%sourcecodester · laboratory management systemMay 14, 2024
- CVE-2024-3330524Monitor
SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Middle Name" parameter in Create User.
MediumCVSS 6.1No exploitEPSS 0%sourcecodester · laboratory management systemMay 2, 2024
- CVE-2025-616022Monitor
SourceCodester Client Database Management System user_customer_create_order.php sql injection
MediumCVSS 5.5No exploitEPSS 1%sourcecodester · downloading client database management systemJun 17, 2025
- CVE-2024-3330721Monitor
SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via "Last Name" parameter in Create User.
MediumCVSS 5.4No exploitEPSS 0%sourcecodester · laboratory management systemMay 1, 2024