Filtered by vendor Sourcecodester Subscriptions
Total 266 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-8469 2 Fabian, Sourcecodester 2 Online Hotel Reservation System, Online Hotel Reservation System 2025-08-05 7.3 High
A vulnerability classified as critical has been found in SourceCodester Online Hotel Reservation System 1.0. This affects an unknown part of the file /admin/deletegallery.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-8470 2 Fabian, Sourcecodester 2 Online Hotel Reservation System, Online Hotel Reservation System 2025-08-05 7.3 High
A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1.0. This vulnerability affects unknown code of the file /admin/deleteroom.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-7408 2 Pushpam02, Sourcecodester 2 Zoo Management System, Zoo Management System 2025-07-16 3.5 Low
A vulnerability has been found in SourceCodester Zoo Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/templates/animal_form_template.php. The manipulation of the argument msg leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-7810 2 Sourcecodester, Tamparongj03 2 Online Graduate Tracer System, Online Graduate Tracer System 2025-07-11 6.3 Medium
A vulnerability was found in SourceCodester Online Graduate Tracer System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /tracking/admin/view_itprofile.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-40394 2 Oretnom23, Sourcecodester 2 Simple Library Management System, Simple Library Management System 2025-07-09 9.8 Critical
Simple Library Management System Project Using PHP/MySQL v1.0 was discovered to contain an arbitrary file upload vulnerability via the component ajax.php.
CVE-2025-6160 1 Sourcecodester 1 Downloading Client Database Management System 2025-06-26 7.3 High
A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /user_customer_create_order.php. The manipulation of the argument user_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-6355 2 Fabianros, Sourcecodester 2 Online Hotel Reservation System, Online Hotel Reservation System 2025-06-26 7.3 High
A vulnerability has been found in SourceCodester Online Hotel Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/execeditroom.php. The manipulation of the argument userid leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-48246 1 Sourcecodester 1 Vehicle Management System 2025-05-21 5.4 Medium
Vehicle Management System 1.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the "Name" parameter of /vehicle-management/booking.php.
CVE-2024-3353 2 Janobe, Sourcecodester 2 Aplaya Beach Resort Online Reservation System, Aplaya Beach Resort Online Reservation System 2025-05-14 7.3 High
A vulnerability was found in SourceCodester Aplaya Beach Resort Online Reservation System 1.0 and classified as critical. This issue affects some unknown processing of the file admin/mod_reports/index.php. The manipulation of the argument categ/end leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259457 was assigned to this vulnerability.
CVE-2024-48594 2 Fast5, Sourcecodester 2 Prison Management System, Prison Management System 2025-05-06 8.8 High
File Upload vulnerability in Prison Management System v.1.0 allows a remote attacker to execute arbitrary code via the file upload component.
CVE-2024-40576 2 Mayurik, Sourcecodester 2 Best House Rental Management System, Best House Rental Management System 2025-05-06 4.7 Medium
Cross Site Scripting vulnerability in Best House Rental Management System 1.0 allows a remote attacker to execute arbitrary code via the "House No" and "Description" parameters in the houses page at the index.php component.
CVE-2024-30849 2 Donbermoy, Sourcecodester 2 Complete E-commerce Site, Complete Ecommerce Site 2025-05-05 9.8 Critical
Arbitrary file upload vulnerability in Sourcecodester Complete E-Commerce Site v1.0, allows remote attackers to execute arbitrary code via filename parameter in admin/products_photo.php.
CVE-2024-44739 2 Oretnom23, Sourcecodester 2 Simple Forum Website, Simple Forum Website 2025-04-30 8.8 High
Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=.
CVE-2024-25239 2 Sourcecodester, Walterjnr1 2 Employee Management System, Employee Management System 2025-04-30 9.8 Critical
SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL commands via crafted POST request to /emloyee_akpoly/Account/login.php.
CVE-2024-52675 2 Oretnom23, Sourcecodester 2 Sentiment Based Movie Rating System, Sentiment Based Movie Rating System 2025-04-24 9.8 Critical
SourceCodester Sentiment Based Movie Rating System 1.0 is vulnerable to SQL Injection in /msrps/movies.php.
CVE-2024-37859 2 Oretnom23, Sourcecodester 2 Lost And Found Information System, Lost And Found Information System 2025-04-23 6.1 Medium
Cross Site Scripting vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the page parameter to php-lfis/admin/index.php.
CVE-2024-37857 2 Oretnom23, Sourcecodester 2 Lost And Found Information System, Lost And Found Information System 2025-04-23 8.8 High
SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via id parameter to php-lfis/admin/categories/view_category.php.
CVE-2024-40402 2 Nikhil-bhalerao, Sourcecodester 2 Simple Library Management System, Simple Library Management System 2025-04-23 6.3 Medium
A SQL injection vulnerability was found in 'ajax.php' of Sourcecodester Simple Library Management System 1.0. This vulnerability stems from insufficient user input validation of the 'username' parameter, allowing attackers to inject malicious SQL queries.
CVE-2024-50766 2 Oretnom23, Sourcecodester 2 Survey Application System, Survey Application System 2025-04-22 9.8 Critical
SourceCodester Survey Application System 1.0 is vulnerable to SQL Injection in takeSurvey.php via the id parameter.
CVE-2024-34230 1 Sourcecodester 1 Laboratory Management System 2025-04-22 6.1 Medium
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the System Information parameter.