PatchSiren

SourceCodester CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW SourceCodester CVE published 2026-08-21

CVE-2026-77392

A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of the file /public/submit.php. This manipulation of the argument Researcher causes sql injection. The attack may be initiated remotely. Evidence is limited; verify affected scope and vendor remediation status. Monitor for public exploit availability and adjust de [truncated]

MEDIUM SourceCodester CVE published 2026-08-20

CVE-2026-76998

The Simple Online Food Ordering System 1.0 is vulnerable to a SQL injection attack in the /admin/ajax.php?action=delete_category file. This vulnerability is caused by improper sanitization of user-supplied input in the ID argument, allowing remote attackers to inject malicious SQL code. The exploit has been publicly disclosed, and the CVSS score is 5.5 (Medium). Administrators and security teams responsib [truncated]

LOW SourceCodester CVE published 2026-08-20

CVE-2026-76997

A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=save_category. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Administrators and users of Simple On [truncated]

MEDIUM SourceCodester CVE published 2026-08-19

CVE-2026-76049

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T04:17:38.277Z and has not been modified since then. This SQL injection vulnerability affects SourceCodester Simple Online Food Ordering System 1.0, specifically in the /admin/ajax.php?action=save_menu file, allowing remote attackers to inject malicious SQL code via the ID argument. System adminis [truncated]

MEDIUM SourceCodester CVE published 2026-08-10

CVE-2026-19384

A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0, specifically a SQL injection vulnerability in an unknown function of the file /admin/ajax.php?action=set_appointment. The vulnerability can be exploited remotely via the ID argument, and a public exploit is available. The affected system may be vulnerable to unauthorized data access or modification. Administrators and [truncated]

MEDIUM SourceCodester CVE published 2026-08-06

CVE-2026-19065

The SourceCodester Online Examination & Learning Management System 1.0 is vulnerable to an unrestricted file upload issue. This CVE record was published on 2026-08-06T22:16:53.773Z and has not been modified since then. The vulnerability affects the file upload_files.php, allowing remote attackers to potentially execute arbitrary code by uploading malicious files. The CVSS score is 5.3 and the severity is [truncated]

CRITICAL SourceCodester CVE published 2026-07-30

CVE-2025-69941

AI-assisted PatchSiren debrief based on the supplied source corpus. CVE-2025-69941 is a critical SQL injection vulnerability in Tailor Management System 1.0, specifically in the addmeasurement.php file. The vulnerability has a CVSS score of 9.8 and is considered critical. The CVE record was published on 2026-07-30T21:16:52.777Z and has not been modified since then. The NVD entry is currently Deferred. Org [truncated]

LOW SourceCodester CVE published 2026-07-21

CVE-2026-16486

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSIS.php. Performing a manipulation of the argument day results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be used. Users should apply patches or mitigations to prevent cross-site scripting attacks.

LOW SourceCodester CVE published 2026-07-21

CVE-2026-16485

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0, affecting an unknown functionality of the file /class.php. Manipulation of the argument day leads to cross-site scripting, which can be launched remotely. The exploit has been disclosed to the public and may be used. Users should apply patches or mitigations to prevent cross-site scripting attacks. This issue has a CVS [truncated]

MEDIUM SourceCodester CVE published 2026-07-19

CVE-2026-16228

A SQL injection vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0, affecting an unknown function in the /edit_schoolyr.php file. The vulnerability can be exploited remotely through manipulation of the ID argument, leading to potential unauthorized access to sensitive data or system compromise. Users of the system should apply patches or mitigations to prevent SQL injection [truncated]

MEDIUM SourceCodester CVE published 2026-07-19

CVE-2026-16227

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /edit_subject.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. Users of SourceCodester Class and Exam Timetabling System 1.0 should apply vendor rem [truncated]

MEDIUM SourceCodester CVE published 2026-07-19

CVE-2026-16226

A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack is possible to be carried out remotely. The vulnerability has a CVSS score of 5.1 and a severity of MEDIUM. Users of SourceCodester Pizzafy Ecommerce System 1.0 should be [truncated]

LOW SourceCodester CVE published 2026-07-19

CVE-2026-16203

A low-severity vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The issue is related to cross-site scripting (XSS) in the /forCYS.php file. The attack vector is remote, and the exploit is publicly available. This vulnerability can be exploited by manipulating the course argument, leading to potential security risks for administrators and users of the system.

LOW SourceCodester CVE published 2026-07-19

CVE-2026-16202

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /CYS.php. This manipulation of the argument course causes cross-site scripting. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vulnerability is a cross-site scripting issue, and us [truncated]

LOW SourceCodester CVE published 2026-07-18

CVE-2026-16156

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /forexam.php. The manipulation of the argument day results in cross site scripting. The vulnerability exists in the /forexam.php file of SourceCodester Class and Exam Timetabling System 1.0. An attacker can inject malicious scripts by manipulating the 'day' argument, leadin [truncated]

LOW SourceCodester CVE published 2026-07-18

CVE-2026-16155

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The vulnerability exists in the /schoolyr.php file and is caused by the manipulation of the argument sy, leading to cross-site scripting. The attack can be initiated remotely, and the exploit is publicly available. Users of the system should apply patches or mitigations to prevent cross-site scripting attacks. The CVSS [truncated]

MEDIUM SourceCodester CVE published 2026-07-18

CVE-2026-16154

A SQL injection vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. The vulnerability affects an unknown functionality of the file /edit_room1.php. A manipulation of the argument ID can lead to SQL injection. The attack may be performed remotely. This vulnerability has been publicly disclosed and may be utilized by attackers. Administrators and users of the system should be aw [truncated]

MEDIUM SourceCodester CVE published 2026-07-18

CVE-2026-16152

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. The affected component is an unknown function of the file /edit_rooma.php. A manipulation of the argument ID results in SQL injection. The attack is possible to be carried out remotely. This vulnerability has a medium severity with a CVSS score of 5.5, indicating a moderate risk to affected systems.

MEDIUM SourceCodester CVE published 2026-07-13

CVE-2026-15597

A SQL injection vulnerability was discovered in SourceCodester Class and Exam Timetabling System 1.0. The vulnerability affects an unknown function of the file /edit_exam2.php. Performing a manipulation of the argument ID results in SQL injection. The attack can be initiated remotely. This vulnerability has a medium severity and requires attention from administrators and users of the system.

LOW SourceCodester CVE published 2026-07-13

CVE-2026-15596

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is an unknown function of the file /subject.php. Such manipulation of the argument subject leads to cross site scripting. It is possible to launch the attack remotely. The vulnerability is a cross-site scripting (XSS) issue in the /subject.php file of SourceCodester Class and Exam Timetabling Syste [truncated]

LOW SourceCodester CVE published 2026-07-13

CVE-2026-15595

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /forsubject.php. This manipulation of the argument subject causes cross-site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vulnerability is a cross-site scripting issue, and users should [truncated]

LOW SourceCodester CVE published 2026-07-13

CVE-2026-15540

A low-severity LFI vulnerability was detected in SourceCodester Online Book Store System 1.0. The affected element is an unknown function of the file /admin/index.php of the component Administrative Interface. Performing a manipulation of the argument page results in improper control of filename for include/require statement in php program. The vulnerability has a CVSS score of 2.1 and is considered low-s [truncated]

MEDIUM SourceCodester CVE published 2026-07-13

CVE-2026-15537

A security flaw has been discovered in SourceCodester Online Book Store System 1.0, affecting the file admin/login.php. The manipulation of the argument Username results in SQL injection, allowing for remote execution of SQL injection attacks. This vulnerability has a CVSS score of 5.5 and is classified as MEDIUM severity. Security teams and administrators responsible for SourceCodester Online Book Store [truncated]

LOW SourceCodester CVE published 2026-07-13

CVE-2026-15532

A vulnerability was identified in Online Book Store System 1.0, affecting the User Management Module. The issue allows for cross-site scripting due to improper handling of user input, such as Name/Username. The attack can be executed remotely. Users should review system configurations and apply necessary patches. This vulnerability has a CVSS score of 1.9, indicating low severity. The exploit is publicly [truncated]

MEDIUM SourceCodester CVE published 2026-07-04

CVE-2026-14652

A SQL injection vulnerability was found in the Simple and Nice Shopping Cart Script 1.0. The vulnerability affects an unknown function of the file /admin/login.php in the Admin Login component. The manipulation of the Username argument results in SQL injection. The attack can be launched remotely. The exploit has been made public and could be used. The CVSS score for this vulnerability is 5.5, with a seve [truncated]

MEDIUM SourceCodester CVE published 2026-07-04

CVE-2026-14642

A SQL injection vulnerability was identified in the Class and Exam Timetabling System 1.0. The vulnerability affects an unknown functionality of the /edit_class2.php file. The manipulation of the ID argument leads to SQL injection. The attack can be carried out remotely. The exploit is publicly available and might be used. The CVSS score for this vulnerability is 5.5, indicating a medium severity level.

MEDIUM SourceCodester CVE published 2026-07-04

CVE-2026-14641

A SQL injection vulnerability was discovered in the SourceCodester Class and Exam Timetabling System 1.0. The issue affects an unknown functionality within the /edit_course.php file. By manipulating the ID argument, an attacker can inject malicious SQL code, enabling remote attacks. The vulnerability has been publicly disclosed and may be exploited. Evidence from Vuldb and NVD confirms the vulnerability's [truncated]

MEDIUM SourceCodester CVE published 2026-06-29

CVE-2026-13527

A SQL injection vulnerability has been discovered in the Class and Exam Timetabling System 1.0. The affected component is an unknown function within the /preview4.php file. This vulnerability allows for SQL injection through manipulation of the course_year_section argument. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The CVSS score for this vulnerabil [truncated]

MEDIUM SourceCodester CVE published 2026-06-28

CVE-2026-13486

CVE-2026-13486 is a SQL injection vulnerability in the SourceCodester Class and Exam Timetabling System 1.0. The vulnerability is located in the /preview6.php file, where an attacker can manipulate the course_year_section argument to inject malicious SQL code. This can be done remotely, and the exploit has been publicly disclosed. The vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. The ven [truncated]

MEDIUM SourceCodester CVE published 2026-06-28

CVE-2026-13485

CVE-2026-13485 is a SQL injection vulnerability in the Class and Exam Timetabling System 1.0. The vulnerability affects an unknown function of the file /preview.php and can be exploited remotely by manipulating the course_year_section argument. The vulnerability has a CVSS score of 5.5 and a severity of MEDIUM. The exploit has been made public and could be used. The vendor is Unknown Vendor, and the produ [truncated]

MEDIUM SourceCodester CVE published 2026-06-17

CVE-2026-12529

CVE-2026-12529 is a MEDIUM severity vulnerability in the SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The vulnerability affects an unknown function of the file /index.php of the component Student Self-Registration Endpoint, allowing for improper access controls. Remote exploitation of the attack is possible. Administrators and users of the system should be aware of this vu [truncated]

LOW SourceCodester CVE published 2026-06-14

CVE-2026-12176

A vulnerability has been found in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The impacted element is an unknown function of the file /index.php. The manipulation of the argument action leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

MEDIUM SourceCodester CVE published 2026-06-08

CVE-2026-11552

A vulnerability has been found in SourceCodester Online Examination & Learning Management System and Syllabus-aligned Learning Management and Examination System 1.0. Affected by this issue is some unknown functionality of the file import_users.php. The manipulation of the argument raw_password with the input CICT_2026 leads to use of hard-coded password. The attack can be initiated remotely.

LOW SourceCodester CVE published 2026-06-08

CVE-2026-11520

A weakness has been identified in SourceCodester Inventory System 1.0. The issue affects an unknown functionality of the file `header.php`, enabling cross-site scripting through manipulation. The attack can be initiated remotely, and a public exploit is available.

LOW SourceCodester CVE published 2026-06-08

CVE-2026-11519

A security flaw has been discovered in SourceCodester Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /Product_Inventory/api/users_handler.php of the component Account Creation Handler. The manipulation of the argument ROLE results in improper authorization. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

MEDIUM SourceCodester CVE published 2026-06-08

CVE-2026-11515

A vulnerability was found in SourceCodester Barangay Resident Profiling and Information Management System 1.0. The affected component is the password reset handler in the file `password_reset.php`. Manipulating the `new_password` argument with the input `password123` leads to the use of a hard-coded password. This attack can be launched remotely. The exploit has been publicly disclosed and may be used.

MEDIUM SourceCodester CVE published 2026-06-08

CVE-2026-11486

A SQL injection vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. The vulnerability affects an unknown functionality of the file /archive1.php and can be exploited remotely. The exploit is publicly available.

MEDIUM SourceCodester CVE published 2026-06-08

CVE-2026-11485

CVE-2026-11485 is a SQL injection vulnerability in SourceCodester Class and Exam Timetabling System 1.0. The vulnerability has a CVSS score of 5.5 and was first published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-11485). The vulnerability affects an unknown function of the file /archive2.php and can be exploited remotely. The vulnerability is caused by manipulation of the argument sy, [truncated]

MEDIUM SourceCodester CVE published 2026-06-08

CVE-2026-11484

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /archive3.php. This manipulation of the argument sy causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.

MEDIUM SourceCodester CVE published 2026-06-08

CVE-2026-11483

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /archive4.php. The manipulation of the argument sy results in SQL injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

MEDIUM SourceCodester CVE published 2026-06-08

CVE-2026-11482

A SQL injection vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. The vulnerability is located in an unknown function of the file /archive5.php and can be exploited remotely by manipulating the 'sy' argument. The vulnerability has a CVSS score of 5.5 and is rated as MEDIUM. The exploit is publicly available and might be used.

MEDIUM SourceCodester CVE published 2026-06-08

CVE-2026-11472

A SQL injection vulnerability was discovered in SourceCodester Class and Exam Timetabling System 1.0. The vulnerability affects an unknown function of the file /index1.php, specifically through manipulation of the Password argument. This vulnerability can be exploited remotely. The exploit has been publicly disclosed and may be utilized.

MEDIUM SourceCodester CVE published 2026-06-08

CVE-2026-11471

A SQL injection vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. The vulnerability is located in an unknown function of the file /index2.php and can be exploited remotely by manipulating the Password argument. The vulnerability has a CVSS score of 5.5 and is rated as MEDIUM.

LOW SourceCodester CVE published 2026-06-08

CVE-2026-11468

A cross-site scripting vulnerability was detected in the SourceCodester Hospitals Patient Records Management System 1.0. The issue affects unknown processing of the file /admin/?page=room_types, where manipulation of the 'room' argument results in cross-site scripting. The attack can be carried out remotely.

MEDIUM SourceCodester CVE published 2026-06-05

CVE-2026-10877

A SQL injection vulnerability has been detected in the SourceCodester Ship Ferry Ticket Reservation System up to version 1.0. The vulnerability affects an unknown function in the `/admin/login.php` file of the Admin Login component. Manipulation of the `Username` argument leads to SQL injection, allowing remote attackers to execute the attack. The exploit has been publicly disclosed and may be used. The C [truncated]

LOW SourceCodester CVE published 2026-06-05

CVE-2026-10876

A weakness has been identified in SourceCodester Ship Ferry Ticket Reservation System 1.0. This affects an unknown function of the file /admin/. This manipulation of the argument page causes improper authorization. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

MEDIUM SourceCodester CVE published 2026-06-01

CVE-2026-10263

A SQL injection vulnerability exists in SourceCodester Computer Repair Shop Management System up to version 1.0. The vulnerability is located in the /admin/products/manage_product.php file, where manipulation of the ID parameter allows an attacker to inject arbitrary SQL commands. The attack vector is network-based and does not require authentication, making it remotely exploitable. The vulnerability has [truncated]

LOW SourceCodester CVE published 2026-06-01

CVE-2026-10248

A CSV injection vulnerability exists in SourceCodester Pharmacy Sales and Inventory System up to version 1.0, specifically within the Supplier Creation Interface. The flaw resides in the create_supplier function of the /Export_csv/export file, where the Address and Company Name parameters are not properly sanitized before being written to CSV output. An attacker with sufficient privileges can inject malic [truncated]

LOW SourceCodester CVE published 2026-06-01

CVE-2026-10247

A stored cross-site scripting (XSS) vulnerability exists in SourceCodester Pharmacy Sales and Inventory System 1.0, specifically within the `create_generic_name` function accessible via the `/ShowForm/create_generic_name/main` endpoint. The `generic_name` parameter lacks sufficient input sanitization, allowing remote attackers to inject malicious scripts. The vulnerability requires low privileges (PR:L) a [truncated]

LOW SourceCodester CVE published 2026-06-01

CVE-2026-10246

A stored cross-site scripting (XSS) vulnerability exists in SourceCodester Pharmacy Sales and Inventory System 1.0, specifically within the create_medicine_presentation function accessible via the /ShowForm/create_medicine_presentation/main endpoint. The medicine_presentation parameter accepts unsanitized input, allowing remote attackers to inject malicious scripts. The vulnerability has been publicly dis [truncated]