SourceCodester vulnerabilities
37 CVEs tracked
Recent reports highlight multiple critical vulnerabilities in PHP-based web applications developed by SourceCodester. The primary issues are SQL Injection and Cross Site Scripting (XSS) flaws identified in 'CASAP Automated Enrollment System 1.0' (CVE-2025-67403, CVE-2025-67404, CVE-2025-67405, CVE-2025-67407, CVE-2025-67408) and 'Class and Exam Timetabling System 1.0' (CVE-2026-16484, CVE-2026-16485, CVE-2026-16486). These flaws could allow remote attackers to manipulate the database. Defenders using this vendor's products should immediately review input validation for parameters in files like `save_stud.php` and `update_class.php`, and consider implementing strict WAF rules.
Azərbaycanca: Son hesabatlarda SourceCodester tərəfindən hazırlanan PHP əsaslı veb tətbiqlərdə çoxsaylı kritik boşluqlar aşkarlanıb. Əsasən 'CASAP Automated Enrollment System 1.0' (CVE-2025-67403, CVE-2025-67404, CVE-2025-67405, CVE-2025-67407, CVE-2025-67408) və 'Class and Exam Timetabling System 1.0' (CVE-2026-16484, CVE-2026-16485, CVE-2026-16486) məhsullarında SQL Injection və Cross Site Scripting (XSS) zəiflikləri qeydə alınıb. Bu boşluqlar uzaqdan hücum edən şəxsə verilənlər bazasını manipulyasiya etməyə imkan yaradır. Müdafiəçilər bu vendorun məhsullarını istifadə edən sistemlərdə dərhal giriş parametrlərinin validasiyasına baxmalı, xüsusilə `save_stud.php`, `update_class.php` kimi fayllara diqqət yetirməli və müvəqqəti WAF qaydaları tətbiq etməyi nəzərdən keçirməlidir.
This vendor's CVEs37
- CVE-2026-76050EPSS 0.33%
- CVE-2026-76049EPSS 0.33%
- CVE-2026-76048EPSS 0.33%
- CVE-2026-75151EPSS 0.15%
- CVE-2026-75080EPSS 0.26%
- CVE-2026-75079EPSS 0.26%
- CVE-2026-75078EPSS 0.27%
- CVE-2026-75014EPSS 0.33%
- CVE-2026-19987EPSS 0.31%
- CVE-2026-19925EPSS 0.21%
- CVE-2026-19904EPSS 0.21%
- CVE-2026-19903EPSS 0.31%
- CVE-2026-19899EPSS 0.26%
- CVE-2026-19839EPSS 0.23%
- CVE-2026-19825EPSS 0.26%
- CVE-2026-19787EPSS 0.21%
- CVE-2026-19384EPSS 0.26%
- CVE-2026-19231EPSS 0.26%
- CVE-2026-19230EPSS 0.20%
- CVE-2026-19229EPSS 0.33%
- CVE-2026-19211EPSS 0.26%
- CVE-2026-19210EPSS 0.28%
- CVE-2026-19209EPSS 0.20%
- CVE-2026-19196EPSS 0.26%
- CVE-2026-16486EPSS 0.47%
- CVE-2026-16485EPSS 0.47%
- CVE-2026-16484EPSS 0.43%
- CVE-2025-69948EPSS 0.31%
- CVE-2025-69947EPSS 0.26%
- CVE-2025-69946EPSS 0.34%
- CVE-2025-69941EPSS 0.26%
- CVE-2025-67408EPSS 0.17%
- CVE-2025-67407EPSS 0.17%
- CVE-2025-67405EPSS 0.17%
- CVE-2025-67404EPSS 0.26%
- CVE-2025-67403EPSS 0.26%
- CVE-2025-65337EPSS 0.15%
This hub is built from skopnix's own reporting on SourceCodester: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.