These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A SQL injection vulnerability exists in SourceCodester Hospitals Patient Records Management System 1.0, specifically in the /classes/Users.php?f=delete endpoint. The ID parameter is susceptible to manipulation, allowing remote attackers to inject arbitrary SQL commands. The vulnerability has been publicly disclosed with an exploit available, though no known active exploitation or ransomware campaign use h [truncated]
Cross-Site Scripting (XSS) vulnerability in SourceCodester Doctor Appointment System 1.0, affecting the user registration functionality in register.php due to improper input sanitization.
A missing authorization vulnerability in SourceCodester eDoc Doctor Appointment System 1.0 allows remote attackers to manipulate the ID parameter in /admin/delete-session.php without proper authentication. The vulnerability was disclosed publicly on 2026-05-26 with proof-of-concept materials available. The CVSS 4.0 vector indicates network attack vector with low attack complexity, no privileges required, [truncated]
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in SourceCodester Student Grades Management System 1.0. The vulnerability affects an unspecified component and can be exploited remotely. According to the source record, an exploit has been publicly released. The vulnerability was published to the CVE List on 2026-05-25 and last modified on 2026-05-26. The CVSS 4.0 vector indicates netw [truncated]
A cross-site scripting (XSS) vulnerability exists in SourceCodester Student Grades Management System 1.0, specifically within the students.php file. The vulnerability stems from improper sanitization of user-supplied input in the 'Remarks' parameter, allowing an attacker to inject malicious scripts. Successful exploitation requires a remote attacker to have low privileges and interact with a victim user i [truncated]
A low-severity improper authorization vulnerability exists in SourceCodester Student Grades Management System 1.0, specifically within the `getClassroomStudents` and `removeStudentFromClassroom` functions of `classroom.php`. The flaw stems from insufficient validation of the `classroom_id` parameter, allowing an authenticated attacker with low privileges to manipulate classroom identifiers and potentially [truncated]
A low-severity improper authorization vulnerability affects SourceCodester Student Grades Management System 1.0. The issue resides in the grades.php file, where manipulation of the student_id parameter allows an attacker with low privileges to bypass authorization controls. The attack vector is network-based, requires low attack complexity, and no user interaction. The vulnerability was disclosed publicly [truncated]
A SQL injection vulnerability exists in SourceCodester Simple POS and Inventory System 1.0, specifically within the /user/search.php file. The vulnerability stems from improper sanitization of the 'Name' parameter, allowing remote attackers to inject malicious SQL commands. The CVSS 4.0 vector indicates network accessibility with low attack complexity, no required privileges or user interaction, and low i [truncated]
A vulnerability in SourceCodester Simple POS and Inventory System 1.0 allows authenticated remote attackers to upload files with unrestricted extensions via the image parameter in /admin/addproduct.php. The flaw stems from improper validation of file extensions in the File Extension Handler component, classified under CWE-434 (Unrestricted Upload of File with Dangerous Type) and CWE-284 (Improper Access C [truncated]
A SQL injection vulnerability exists in SourceCodester Simple POS and Inventory System 1.0, specifically within the delete function of /admin/deleteproduct.php. The vulnerability stems from improper sanitization of the ID parameter in GET requests, allowing remote attackers to manipulate database queries. The CVSS 4.0 score of 2.0 (LOW severity) reflects the requirement for high privileges (PR:H), though [truncated]
A stored cross-site scripting (XSS) vulnerability exists in SourceCodester Indian Invoicing System up to version 1.0. The flaw resides in the `customer_name` parameter of `/Invoicing/add_order.php`, allowing remote attackers to inject malicious scripts that execute in the context of authenticated users. The vulnerability has been publicly disclosed with proof-of-concept material available. The CVSS 4.0 ve [truncated]
A cross-site scripting (XSS) vulnerability exists in SourceCodester Indian Invoicing System 1.0, specifically within the `/Invoicing/category.php` file. The `msg` parameter is susceptible to manipulation, allowing remote attackers to inject malicious scripts. The CVSS 4.0 vector indicates network attack vector with low attack complexity, no privileges required, but user interaction is required. The vulner [truncated]
A low-severity improper access control vulnerability affects SourceCodester Indian Invoicing System 1.0. The vulnerability resides in an unspecified backend endpoint and allows remote attackers to manipulate access controls. The issue was published on May 25, 2026, and modified on May 26, 2026. The exploit has been publicly disclosed and may be utilized. Multiple endpoints are affected. The vulnerability [truncated]
A SQL injection vulnerability exists in SourceCodester Indian Invoicing System 1.0, specifically within the /Invoicing/IGST_Invoice.php file's Invoice Generation Handler component. The vulnerability allows remote attackers to manipulate the customer_name or category parameters to inject malicious SQL commands. The CVSS 4.0 vector indicates network attack vector with low attack complexity, requiring low pr [truncated]
A stored cross-site scripting (XSS) vulnerability exists in SourceCodester SUP Online Shopping 1.0, specifically within the administrative product editing interface at /admin/productedit.php. The productName parameter lacks proper input sanitization, allowing authenticated administrators to inject malicious scripts. Successful exploitation requires high privileges (administrative access) and user interact [truncated]
A SQL injection vulnerability exists in SourceCodester Hospitals Patient Records Management System 1.0, specifically in the /classes/Master.php?f=save_patient_history endpoint. The vulnerability stems from improper sanitization of the 'ID' parameter, allowing remote attackers to inject malicious SQL commands. The CVSS 4.0 vector indicates network attack vector with low attack complexity, no privileges req [truncated]
A SQL injection vulnerability exists in SourceCodester Hospitals Patient Records Management System 1.0, specifically within the /admin/patients/view_history.php file. The vulnerability stems from improper input validation of the ID parameter, allowing remote attackers to manipulate SQL queries. The CVSS 4.0 vector indicates network attack vector with low attack complexity, no required privileges, and no u [truncated]
A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation of the argument Name can lead to cross site scripting. The attack can be executed remotely. This issue has been publicly disclosed and may be utilized by attackers. Administrators and users should be aware of [truncated]
A low-severity vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. The vulnerability affects the function save_order of the file /admin/ajax.php?action=save_order and allows for cross-site scripting via manipulation of the argument first_name. Remote exploitation is possible. The exploit has been made public. This vulnerability has a CVSS score of 1.9, indicating low severity. Administ [truncated]
A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu. Such manipulation of the argument Name leads to cross site scripting. The attack may be launched remotely. This issue affects users of the system who have not applied patches or mitigations.
A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0, specifically in the file /index.php?page=types. The vulnerability allows for cross-site scripting (XSS) attacks through manipulation of the ID argument. This issue can be exploited remotely, potentially leading to unauthorized actions or data exposure. Users of the affected system should apply patches or mitigations to preven [truncated]
A security flaw has been discovered in SourceCodester Pharmacy Product Management System 1.0. This affects an unknown part of the file add-sales.php of the component POST Parameter Handler. Performing a manipulation of the argument txtqty results in business logic errors. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. Security teams [truncated]
A vulnerability was identified in Online Food Ordering System 1.0. The function save_product of the file /Actions.php is affected by manipulation of the argument price, leading to business logic errors. The attack may be performed remotely. This issue has a CVSS score of 2.1 and is considered Low severity. Users should be aware of this vulnerability and take necessary precautions to prevent exploitation.
A flaw has been found in SourceCodester Sales and Inventory System 1.0. Affected is an unknown function of the file /delete.php of the component GET Parameter Handler. This manipulation of the argument ID causes cross site scripting. Remote exploitation of the attack is possible. The vulnerability allows attackers to inject malicious scripts into the application, potentially leading to unauthorized action [truncated]
CVE-2026-5531 is a cleartext storage vulnerability in the SourceCodester Student Result Management System 1.0. The vulnerability is located in the /login_credentials.txt file and can be exploited remotely via an HTTP GET request. The attack complexity is low, and the CVSS score is 5.5 (MEDIUM). Administrators and users should be aware of this vulnerability and take necessary actions to mitigate it. The vu [truncated]
CVE-2026-5210 is a Local File Inclusion (LFI) vulnerability in SourceCodester Leave Application System 1.0. The vulnerability allows remote attackers to include files via manipulation of the 'page' argument. This could lead to unauthorized access, data breaches, or system compromise. Organizations should prioritize patching to prevent potential remote file inclusion attacks.
A security vulnerability has been detected in SourceCodester Leave Application System 1.0. Affected by this issue is some unknown functionality of the component User Management Handler. Such manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. This issue requires specific conditions to be exploited and has a low CVSS score of 1.9.
CVE-2026-30521 is a Business Logic vulnerability in SourceCodester Loan Management System v1.0. The application allows administrators to create 'Loan Plans' with specific interest rates. While the frontend interface prevents users from entering negative numbers, this constraint is not enforced on the backend. An authenticated attacker can bypass the client-side restriction by manipulating the HTTP POST re [truncated]
CVE-2025-70141 is a critical vulnerability in the SourceCodester Customer Support System 1.0. The system's AJAX dispatcher in ajax.php fails to enforce authentication or authorization before executing administrative methods in admin_class.php based on the action parameter. This allows an unauthenticated remote attacker to perform sensitive operations, including creating customers, deleting users (includin [truncated]