Vendor
SourceCodester vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 218 vulnerabilities in SourceCodester: 0 in the last 7 days and 136 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-92927, was published on 17 September 2026. 23 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 136
- Critical, all time
- 1
- Exploited in the wild
- 0
About SourceCodester
SourceCodester is a platform that provides free source code and tutorials for various programming languages and web applications.
SourceCodester technologies
- SourceCodester Class and Exam Timetabling System56
- SourceCodester Inventory Management System16
- SourceCodester Simple Online Food Ordering System10
- SourceCodester Pharmacy Sales and Inventory System9
- SourceCodester CET Automated Grading System with AI Predictive Analytics7
- SourceCodester Syllabus-Aligned Learning Management & Examination System7
- SourceCodester Multi-Vendor Online Grocery Management System6
- SourceCodester Online-Examination-And-Learning-Management-System6
- SourceCodester Pizzafy Ecommerce System6
- SourceCodester CASAP Automated Enrollment System5
- SourceCodester Hospitals Patient Records Management System5
- SourceCodester Simple and Nice Shopping Cart Script5
- SourceCodester Student Grades Management System5
- SourceCodester Indian Invoicing System4
- SourceCodester Online Book Store System4
- SourceCodester Online Faculty Clearance System4
- SourceCodester School Registration and Fee System4
- SourceCodester Simple POS and Inventory System4
- SourceCodester College Notes Gallery Management System3
- SourceCodester Hospital's Patient Records Management System3
- SourceCodester Online Food Ordering System3
- SourceCodester Ship Ferry Ticket Reservation System3
- SourceCodester Simple Traffic Offense System3
Latest SourceCodester vulnerabilities
- CVE-2026-92927: SourceCodester Drug Recommendation System hardcoded credentials disclosuremediumCVSS 5.3EPSS 0.5%
- CVE-2026-92406: SourceCodester Inventory and Monitoring System SQL injection in btn_functions.phphighCVSS 7.3EPSS 0.4%
- CVE-2026-92405: SourceCodester Inventory and Monitoring System SQL injection in /index.phphighCVSS 7.3EPSS 0.4%
- CVE-2026-92385: SourceCodester Online Food Ordering System stored XSS in category image uploadlowCVSS 2.4EPSS 0.4%
- CVE-2026-91005: SourceCodester Online Faculty Clearance System arbitrary file uploadmediumCVSS 6.3EPSS 0.4%
- CVE-2026-91004: SourceCodester Online Faculty Clearance System SQL injection in delete_faculty1.phphighCVSS 7.3EPSS 0.4%
- CVE-2026-90877: SourceCodester Online Faculty Clearance System SQL injection in update_requirement_status.phphighCVSS 7.3EPSS 0.4%
- CVE-2026-90876: SourceCodester Online Faculty Clearance System SQL injection in delete_requirement.phphighCVSS 7.3EPSS 0.4%
- CVE-2026-90857: SourceCodester College Notes Gallery Management System arbitrary file uploadmediumCVSS 6.3EPSS 0.4%
- CVE-2026-90856: SourceCodester College Notes Gallery Management System privilege escalation in signuphighCVSS 7.3EPSS 0.5%
- CVE-2026-90855: SourceCodester katojkalemba Online Food Ordering System SQL injection in order.phphighCVSS 7.3EPSS 0.4%
- CVE-2026-90854: SourceCodester katojkalemba Online Food Ordering System SQL injectionhighCVSS 7.3EPSS 0.4%
- CVE-2026-90849: SourceCodester College Notes Gallery Management System SQL injection in loginhighCVSS 7.3EPSS 0.4%
- CVE-2026-90697: SourceCodester Inventory Management System IDOR in invoice.phpmediumCVSS 4.3EPSS 0.4%
- CVE-2026-90696: SourceCodester Inventory Management System stored XSS in product namelowCVSS 3.5EPSS 0.4%
- CVE-2026-90695: SourceCodester Inventory Management System stored XSS in Vendor ManagementlowCVSS 3.5EPSS 0.4%
- CVE-2026-90694: SourceCodester Inventory Management System stored XSS in customer namelowCVSS 3.5EPSS 0.4%
- CVE-2026-90615: SourceCodester Class and Exam Timetabling System XSS in subject parametermediumCVSS 4.3EPSS 0.5%
- CVE-2026-90526: SourceCodester School Registration and Fee System SQL injection in save_class.phphighCVSS 7.3EPSS 0.4%
- CVE-2026-90516: SourceCodester School Registration and Fee System SQL injection in pay_report.phphighCVSS 7.3EPSS 0.4%
- CVE-2026-90515: SourceCodester School Registration and Fee System SQL injection in delete_stud.phphighCVSS 7.3EPSS 0.4%
- CVE-2026-90514: SourceCodester School Registration and Fee System SQL injectionhighCVSS 7.3EPSS 0.4%
- CVE-2026-86298: SourceCodester Class and Exam Timetabling System SQL injection in /delete_subject.phphighCVSS 7.3EPSS 0.4%
- CVE-2026-86294: SourceCodester Simple Traffic Offense System stored XSS in settingsmediumCVSS 4.3EPSS 0.5%
- CVE-2026-86293: SourceCodester Simple Traffic Offense System auth bypass in delete endpointsmediumCVSS 6.5EPSS 0.8%
Most severe SourceCodester vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-36236: SourceCodester Engineers Online Portal SQL injection in update_password.phpcriticalCVSS 9.8
- CVE-2026-86292: SourceCodester Simple Traffic Offense System auth bypass in user creationhighCVSS 7.3EPSS 0.7%
- CVE-2026-86277: SourceCodester Syllabus-Aligned Learning Management System authorization bypasshighCVSS 7.3EPSS 0.5%
- CVE-2026-90856: SourceCodester College Notes Gallery Management System privilege escalation in signuphighCVSS 7.3EPSS 0.5%
- CVE-2026-86276: SourceCodester Syllabus-Aligned Learning Management & Examination System hardcoded credentials and SQL injectionhighCVSS 7.3EPSS 0.5%
- CVE-2026-85512: SourceCodester Class and Exam Timetabling System authorization bypass in /admin/session.phphighCVSS 7.3EPSS 0.5%
- CVE-2026-90849: SourceCodester College Notes Gallery Management System SQL injection in loginhighCVSS 7.3EPSS 0.4%
- CVE-2026-86223: SourceCodester Class and Exam Timetabling System SQL injection in course parameterhighCVSS 7.3EPSS 0.4%
- CVE-2026-78197: SourceCodester Simple Online Food Ordering System SQL injection in admin AJAXhighCVSS 7.3EPSS 0.4%
- CVE-2026-92406: SourceCodester Inventory and Monitoring System SQL injection in btn_functions.phphighCVSS 7.3EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 33 | 0 | |
| 6 Jul 2026 | 3 | 0 | |
| 13 Jul 2026 | 18 | 0 | |
| 20 Jul 2026 | 3 | 0 | |
| 27 Jul 2026 | 11 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 2 | 0 | |
| 17 Aug 2026 | 15 | 0 | |
| 24 Aug 2026 | 6 | 0 | |
| 31 Aug 2026 | 10 | 0 | |
| 7 Sep 2026 | 15 | 0 | |
| 14 Sep 2026 | 18 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/sourcecodester.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "SourceCodester vulnerabilities", https://junglewise.ai/threats/vendors/sourcecodester, 26 September 2026.