PatchSiren

SourceCodester CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM SourceCodester CVE published 2026-10-06

CVE-2026-105705

A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0, impacting the file Admin/add_drug.php with a cross-site scripting vulnerability. The attack can be carried out remotely. The exploit has been released to the public and may be used for attacks. This vulnerability affects the Drug Recommendation System 1.0, specifically within the Admin/add_drug.php file, allowing for cro [truncated]

MEDIUM SourceCodester CVE published 2026-10-05

CVE-2026-105247

A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/Subject/btn_functions.php?action=course. Executing a manipulation of the argument Subject can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.

MEDIUM SourceCodester CVE published 2026-10-05

CVE-2026-105246

A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/Subject/btn_functions.php?action=update. Performing a manipulation of the argument Subject results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.

MEDIUM SourceCodester CVE published 2026-10-05

CVE-2026-105182

A security flaw has been discovered in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/activities/btn_functions.php?action=update. The manipulation of the argument Title results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

LOW SourceCodester CVE published 2026-10-05

CVE-2026-105179

A weakness in SourceCodester Drug Recommendation System 1.0's password handler allows for missing encryption of sensitive data. The vulnerability is located in the Admin/add_user.php file and can be exploited remotely by manipulating the Password argument. This issue may impact defenders who need to verify the system's password handling and encryption mechanisms to protect sensitive data. The CVE record a [truncated]

LOW SourceCodester CVE published 2026-10-05

CVE-2026-105178

A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. The impacted element is the function mysqli_real_escape_string of the file /Admin/add_symptom.php of the component Symptom Creation. Performing a manipulation of the argument txtname results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.

LOW SourceCodester CVE published 2026-10-05

CVE-2026-105177

A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. The affected element is an unknown function of the file /Admin/add_drug.php of the component Drug Creation. Such manipulation of the argument txtname/cmdtype/txtusage/txtsideeffect/cmdcontraindication leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.

LOW SourceCodester CVE published 2026-10-05

CVE-2026-105176

A vulnerability was determined in SourceCodester Drug Recommendation System 1.0. Impacted is an unknown function of the file /Admin/edit_class.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. Defenders should assess exposure and prioritize patching or mitigation to prevent potenti [truncated]

MEDIUM SourceCodester CVE published 2026-10-05

CVE-2026-105175

A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /Auth/add_student.php of the component Student Registration. The manipulation of the argument cmdschool results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. The vulnerability allows remote attackers to execute arbit [truncated]

MEDIUM SourceCodester CVE published 2026-09-23

CVE-2026-95924

A SQL injection vulnerability was found in the Online Reviewer Management System 1.0, specifically in the /reviewer_0/admins/assessments/databank/btn_functions.php?action=add file. The vulnerability is caused by the manipulation of the difficulty_id argument. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

LOW SourceCodester CVE published 2026-09-20

CVE-2026-94035

A vulnerability was determined in SourceCodester Drug Recommendation System 1.0. Impacted is an unknown function of the file /drug_recommender/index.php. Executing a manipulation of the argument full name can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Defenders should assess their exposure and prioritize verification of t [truncated]

LOW SourceCodester CVE published 2026-09-20

CVE-2026-94034

A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /drug_recommender/Admin/change_password of the component Password Change. Performing a manipulation of the argument txtoldpassword/txtnewpassword results in cross site scripting. The attack can be initiated remotely. The vulnerability has been made public and could be used. De [truncated]

LOW SourceCodester CVE published 2026-09-20

CVE-2026-94033

A vulnerability has been found in SourceCodester Drug Recommendation System 1.0. This vulnerability affects unknown code of the file /drug_recommender/Admin/add_user of the component User Management. Such manipulation of the argument txtname/txtemail/txtpassword leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

LOW SourceCodester CVE published 2026-09-20

CVE-2026-94016

A security flaw has been discovered in SourceCodester Drug Recommendation System 1.0. This impacts an unknown function of the file /drug_recommender/Admin/add_symptom. Performing a manipulation of the argument txtname results in cross site scripting. Remote exploitation of the attack is possible. The vulnerability allows an attacker to inject malicious code, potentially leading to cross-site scripting att [truncated]

MEDIUM SourceCodester CVE published 2026-09-20

CVE-2026-94015

A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the file /drug_recommender/Admin/edit_user.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used. Defenders should assess exposure and prioritize verification and mitigation efforts for syst [truncated]

MEDIUM SourceCodester CVE published 2026-09-20

CVE-2026-93997

A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected by this issue is some unknown functionality of the file /Admin/edit_symptom.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

MEDIUM SourceCodester CVE published 2026-09-20

CVE-2026-93973

A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admins/assessments/subject/btn_functions.php?action=remove. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.

MEDIUM SourceCodester CVE published 2026-09-20

CVE-2026-93972

A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/course/btn_functions.php. Such manipulation of the argument courseID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

MEDIUM SourceCodester CVE published 2026-09-20

CVE-2026-93959

A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown processing of the file /reviewer_0/admins/assessments/course/btn_functions.php. This manipulation of the argument Course causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

MEDIUM SourceCodester CVE published 2026-09-17

CVE-2026-92927

A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /db/drug_recommendor.sql. Performing a manipulation results in information disclosure. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Defenders should assess exposure and verify vendor remediation to prevent potential inf [truncated]

LOW SourceCodester CVE published 2026-09-16

CVE-2026-92385

A vulnerability was found in the Online Food Ordering System 1.0, specifically in the /admin/update_category.php file of the Category Update component. The vulnerability allows for cross-site scripting (XSS) and can be exploited remotely. The exploit has been publicly disclosed. To address this vulnerability, defenders and administrators should assess the exposure of their systems, review security configu [truncated]

MEDIUM SourceCodester CVE published 2026-09-13

CVE-2026-90515

A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown function of the file /bilal/normal/delete_stud.php. Executing a manipulation of the argument selector[] can lead to sql injection. The attack can be launched remotely. This vulnerability can be exploited remotely, and defenders should verify the presence of the vulnerable file and as [truncated]

MEDIUM SourceCodester CVE published 2026-09-07

CVE-2026-86298

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /delete_subject.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. This vulnerability could allow attackers to manipulate dat [truncated]

LOW SourceCodester CVE published 2026-09-07

CVE-2026-86294

A vulnerability was found in the SourceCodester Simple Traffic Offense System 1.0, affecting the settings update endpoint. This issue allows for cross-site scripting due to improper handling of the site_name and site_desc arguments. Although remote exploitation is possible, the CVSS score is low at 2.1, indicating a limited attack surface. The exploit has been publicly disclosed, which may increase the ri [truncated]

MEDIUM SourceCodester CVE published 2026-09-07

CVE-2026-86293

A vulnerability was found in SourceCodester Simple Traffic Offense System 1.0, specifically in the file delete-user.php of the Deletion Endpoint. This flaw allows for missing authentication due to improper handling of the ID argument. The attack can be launched remotely. However, there is limited information available regarding the exploitability, impact, and affected versions of this vulnerability.

MEDIUM SourceCodester CVE published 2026-09-07

CVE-2026-86292

A vulnerability was detected in SourceCodester Simple Traffic Offense System 1.0, specifically in the saveuser.php file of the User Creation component. The vulnerability results in missing authentication due to manipulation of the position argument, and it can be initiated remotely. The exploit is now public and may be used. This vulnerability has a medium severity level and defenders should assess the ex [truncated]

MEDIUM SourceCodester CVE published 2026-09-07

CVE-2026-86290

A weakness has been identified in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /voting/ajax.php?action=save_category. This manipulation of the argument Category causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vulnerability is located in the /voting/ajax.php?action=save_ [truncated]

LOW SourceCodester CVE published 2026-09-07

CVE-2026-86281

A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0, impacting an unknown function with cross-site request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Defenders should assess exposure and prioritize verification and mitigation efforts. The vulnerability affects an unk [truncated]

MEDIUM SourceCodester CVE published 2026-09-07

CVE-2026-86280

A vulnerability was identified in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This affects an unknown function of the file cict_portal.sql. Such manipulation leads to cleartext storage of sensitive information. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vulnerability has been confirmed to exist in the specified v [truncated]

LOW SourceCodester CVE published 2026-09-07

CVE-2026-86279

A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The impacted element is an unknown function of the file auth_process.php of the component Login. This manipulation causes session fixiation. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.