Vendor
SQL Injection in SourceCodester Inventory and Monitoring System
1 rule 1 TTP 1 CVESourceCodester Inventory and Monitoring System 1.0 is vulnerable to remote SQL injection via the Username argument in index.php, allowing unauthenticated attackers to execute arbitrary database commands.
SQL Injection in SourceCodester Online Faculty Clearance System
1 rule 1 TTP 1 CVESourceCodester Online Faculty Clearance System 1.0 is vulnerable to remote SQL injection in /delete_requirement.php via the ID argument, allowing unauthorized database access.
SQL Injection Vulnerability in Online Food Ordering System
1 rule 1 TTP 1 CVEOnline Food Ordering System 1.0 contains a SQL injection vulnerability in /web/category-foods.php that allows remote, unauthenticated attackers to execute arbitrary database queries via the ID argument.
SQL Injection in SourceCodester College Notes Gallery Management System
1 rule 2 TTPs 1 CVESourceCodester College Notes Gallery Management System version 1.0 contains a SQL injection vulnerability in the login.php file, allowing unauthenticated remote attackers to execute arbitrary database queries.
SQL Injection in SourceCodester School Registration and Fee System
1 rule 1 TTP 1 CVECVE-2026-90514 is a remote SQL injection vulnerability in the School Registration and Fee System 1.0 that allows unauthenticated attackers to execute arbitrary database queries via the Status parameter.
Authentication Bypass in SourceCodester Simple Traffic Offense System
1 rule 1 TTP 1 CVEAn authentication bypass vulnerability in SourceCodester Simple Traffic Offense System 1.0 allows remote, unauthenticated attackers to manipulate user creation via the saveuser.php script.
Hard-Coded Credentials in SourceCodester Syllabus-Aligned Learning Management & Examination System
1 TTP 1 CVESourceCodester Syllabus-Aligned Learning Management & Examination System 1.0 contains a vulnerability in db.php that allows remote attackers to gain unauthorized access via hard-coded credentials.
SQL Injection in SourceCodester Online Voting System
3 rules 1 TTP 1 CVESourceCodester Online Voting System 1.0 is vulnerable to remote SQL injection via the 'id' parameter in the '/ajax.php?action=save_user' endpoint, enabling unauthenticated attackers to manipulate database queries.
Authorization Bypass in SourceCodester Class and Exam Timetabling System
2 rules 1 TTP 1 CVESourceCodester Class and Exam Timetabling System version 1.0 is vulnerable to a remote authorization bypass via the ID argument in /admin/session.php, enabling unauthenticated access to administrative functions.
SQL Injection Vulnerability in Simple Online Food Ordering System
1 rule 1 TTP 1 CVEA SQL injection vulnerability in SourceCodester Simple Online Food Ordering System version 1.0 allows unauthenticated remote attackers to manipulate database queries via the email parameter in /admin/ajax.php.
Path Traversal Vulnerability in SourceCodester SRMS
1 rule 1 TTP 1 CVESourceCodester Student Result Management System 1.0 contains a path traversal vulnerability (CVE-2025-4720) in the drop_student.php endpoint, allowing authenticated attackers to perform arbitrary file deletion via the 'img' parameter.
SQL Injection in Simple Online Food Ordering System
2 rules 1 TTP 1 CVESourceCodester Simple Online Food Ordering System 1.0 is vulnerable to unauthenticated SQL injection via the admin login endpoint, allowing remote attackers to execute arbitrary SQL commands.
SQL Injection in SourceCodester Pet Grooming Management Software
1 rule 1 TTP 1 CVEA publicly exploitable SQL injection vulnerability in SourceCodester Pet Grooming Management Software 1.0 allows remote attackers to compromise the backend database via the /admin/get_barcode_data.php file.
SQL Injection in SourceCodester Class and Exam Timetabling System
2 rules 1 TTP 1 CVESourceCodester Class and Exam Timetabling System 1.0 contains an unauthenticated SQL injection vulnerability in edit_teacher.php that allows remote attackers to compromise database integrity.
SQL Injection in SourceCodester Simple Client Management System
1 rule 1 TTP 1 CVEAn unauthenticated remote SQL injection vulnerability exists in the SourceCodester Simple Client Management System 1.0 that allows attackers to manipulate database queries via the ID parameter.
SQL Injection Vulnerability in SourceCodester Simple Student Information System
1 rule 1 TTP 1 CVEAn unauthenticated remote SQL injection vulnerability in SourceCodester Simple Student Information System allows attackers to execute arbitrary database commands via the 'ID' parameter in 'view_department.php'.
SQL Injection in SourceCodester Simple Doctors Appointment System
1 rule 2 TTPs 2 CVEsSourceCodester Simple Doctors Appointment System 1.0 is vulnerable to remote SQL injection via the 'ID' parameter in the '/admin/ajax.php?action=delete_appointment' endpoint, with public exploit code currently available.
SQL Injection in SourceCodester Photo Share Website
1 rule 1 TTPSourceCodester Photo Share Website 1.0 contains an SQL injection vulnerability in the login function of the /social/ajax.php script, allowing remote attackers to execute arbitrary SQL commands via the email parameter.
SQL Injection in SourceCodester Computer Repair Shop Management System
1 rule 2 TTPs 1 CVEAn unauthenticated remote SQL injection vulnerability exists in the SourceCodester Computer Repair Shop Management System version 1.0 due to improper sanitization of the 'id' parameter in the delete_product function.
Remote SQL Injection Vulnerability in SourceCodester Class and Exam Timetabling System (CVE-2026-16484)
1 rule 2 TTPs 1 CVEA remote SQL injection vulnerability (CVE-2026-16484) exists in SourceCodester Class and Exam Timetabling System 1.0, specifically within the /edit_subjecta.php file, allowing an unauthenticated attacker to manipulate the 'ID' argument to inject malicious SQL commands, potentially leading to data compromise or unauthorized access, with public exploits available.
CVE-2026-16227: SourceCodester Class and Exam Timetabling System SQL Injection
1 rule 1 TTP 2 CVEsA high-severity SQL injection vulnerability (CVE-2026-16227) in SourceCodester Class and Exam Timetabling System 1.0 allows remote, unauthenticated attackers to execute arbitrary SQL commands by manipulating the 'ID' argument in the '/edit_subject.php' file, with the exploit publicly disclosed.
SQL Injection Vulnerability in SourceCodester Class and Exam Timetabling System (CVE-2026-16152)
1 rule 2 TTPs 2 CVEsAn unauthenticated remote attacker can exploit CVE-2026-16152, a SQL injection vulnerability in SourceCodester Class and Exam Timetabling System version 1.0, by manipulating the `ID` argument within the `/edit_rooma.php` file, potentially leading to unauthorized database access and data compromise, with a public exploit available.
Critical SQL Injection Vulnerability in SourceCodester Simple and Nice Shopping Cart Script (CVE-2026-15703)
1 rule 2 TTPs 1 CVEA critical SQL injection vulnerability, identified as CVE-2026-15703, exists in SourceCodester Simple and Nice Shopping Cart Script version 1.0, allowing remote attackers to execute arbitrary SQL commands by manipulating the 'user_id' argument in '/admin/userproductdeletequery.php', with a public exploit enabling unauthorized data access, modification, or deletion.
CVE-2026-15537: SQL Injection Vulnerability in SourceCodester Online Book Store System 1.0
1 TTP 1 CVEA remote SQL injection vulnerability (CVE-2026-15537) has been identified in SourceCodester Online Book Store System 1.0. The flaw is located in the `admin/login.php` file, specifically impacting the 'Username' argument, and allows for authentication bypass. This vulnerability can be exploited remotely, and a public exploit is available.
CVE-2026-15190: SQL Injection in SourceCodester Simple and Nice Shopping Cart Script
1 rule 3 TTPs 1 CVE 3 IOCsA critical SQL injection vulnerability (CVE-2026-15190) exists in SourceCodester Simple and Nice Shopping Cart Script version 1.0, allowing unauthenticated remote attackers to bypass authentication and potentially exfiltrate sensitive data by manipulating the 'Username' argument on the `/login.php` page, with a public exploit now available.
CVE-2026-14778: Improper Authorization in SourceCodester Onlne Examination & Learning Management System
1 CVEA high-severity improper authorization vulnerability (CVE-2026-14778) exists in SourceCodester Onlne Examination & Learning Management System version 1.0, allowing remote attackers to bypass authorization checks by manipulating the `student_id`, `schedule_id`, or `action` arguments in `/ajax_enroll.php`, potentially leading to unauthorized access or actions.
CVE-2026-14771: SourceCodester Class and Exam Timetabling System SQL Injection Vulnerability
1 rule 1 TTP 1 CVE 6 IOCsA critical SQL injection vulnerability (CVE-2026-14771) has been discovered in SourceCodester Class and Exam Timetabling System version 1.0, allowing remote unauthenticated attackers to manipulate the 'ID' argument in `/edit_exam1.php`, leading to arbitrary SQL command execution and potential data compromise.
CVE-2026-14770: SourceCodester Class and Exam Timetabling System SQL Injection Vulnerability
1 rule 1 TTP 1 CVEA high-severity SQL injection vulnerability, CVE-2026-14770, exists in SourceCodester Class and Exam Timetabling System version 1.0 within the `/edit_room.php` file, allowing remote, unauthenticated attackers to manipulate the 'ID' argument with public exploits, leading to data exposure and potential database compromise.
CVE-2026-14734: SQL Injection in SourceCodester Class and Exam Timetabling System
1 rule 3 TTPs 1 CVE 6 IOCsA high-severity SQL injection vulnerability (CVE-2026-14734) exists in SourceCodester Class and Exam Timetabling System version 1.0, allowing unauthenticated remote attackers to manipulate the 'ID' argument in `/edit_product.php` to execute arbitrary SQL queries, with a publicly available exploit increasing the risk of unauthorized data access, modification, or exfiltration.
CVE-2026-14733: Remote SQL Injection in SourceCodester Class and Exam Timetabling System
1 rule 2 TTPs 1 CVEA high-severity SQL injection vulnerability, CVE-2026-14733, exists in SourceCodester Class and Exam Timetabling System 1.0, specifically within the '/edit_coursea.php' file, allowing unauthenticated remote attackers to manipulate the 'ID' argument and execute arbitrary SQL commands due to a publicly available exploit.
CVE-2026-14732: SQL Injection in SourceCodester Class and Exam Timetabling System
1 rule 1 TTP 1 CVEA critical SQL injection vulnerability (CVE-2026-14732) in SourceCodester Class and Exam Timetabling System 1.0 allows remote, unauthenticated attackers to execute arbitrary SQL commands via manipulation of the `ID` argument in `/edit_exam.php`, leading to data exfiltration and potential system compromise.
CVE-2026-14719: SourceCodester Onlne Examination & Learning Management System Privilege Escalation
1 rule 2 TTPs 1 CVE 1 IOCA critical remote vulnerability (CVE-2026-14719) has been identified in SourceCodester Onlne Examination & Learning Management System version 1.0. The flaw resides in the Registration Endpoint, specifically within the 'register.php' file, where improper privilege management allows for manipulation of the 'role' argument, leading to unauthorized privilege escalation. A public exploit for this vulnerability has been published, increasing the immediate risk of exploitation.
CVE-2026-14713 — SQL Injection in SourceCodester Pizzafy E-Commerce System
1 rule 1 TTP 1 CVEA critical SQL injection vulnerability (CVE-2026-14713) exists in SourceCodester Pizzafy E-Commerce System version 1.0, allowing unauthenticated remote attackers to execute arbitrary SQL commands by manipulating the 'ID' argument in the `/admin/ajax.php?action=confirm_order` endpoint, potentially leading to data exfiltration or modification, with a public exploit available.
CVE-2026-14695: SourceCodester Multi-Vendor Online Grocery Management System SQL Injection
1 TTP 1 CVEA high-severity SQL injection vulnerability, CVE-2026-14695, exists in SourceCodester Multi-Vendor Online Grocery Management System 1.0, allowing remote attackers to manipulate the 'Name' argument within the `save_client` function of `classes/Users.php` to execute arbitrary SQL commands, with a public exploit available.
CVE-2026-14690: Improper Authorization in SourceCodester Multi-Vendor Online Grocery Management System
3 TTPs 1 CVEA high-severity improper authorization vulnerability (CVE-2026-14690) in the `save_users` function of SourceCodester Multi-Vendor Online Grocery Management System 1.0 allows remote unauthenticated attackers to manipulate user accounts, potentially leading to privilege escalation or unauthorized access, with a public exploit readily available.
CVE-2026-14654: Remote SQL Injection in SourceCodester Simple and Nice Shopping Cart Script
1 rule 1 TTP 1 CVE 7 IOCsA remote, unauthenticated SQL injection vulnerability (CVE-2026-14654) in SourceCodester Simple and Nice Shopping Cart Script 1.0 allows attackers to manipulate the `user_id` argument via `/admin/girlsproductdeletequery.php`, leading to database compromise, data exfiltration, or unauthorized access, with an exploit publicly available.
CVE-2026-14652: SQL Injection in SourceCodester Simple and Nice Shopping Cart Script
1 rule 1 TTP 1 CVEA critical SQL injection vulnerability (CVE-2026-14652) exists in the Admin Login component of SourceCodester Simple and Nice Shopping Cart Script version 1.0, allowing an unauthenticated attacker to remotely exploit it by manipulating the 'Username' argument in the /admin/login.php file, potentially leading to unauthorized access, information disclosure, or data manipulation, with a public exploit available.
SQL Injection in SourceCodester Class and Exam Timetabling System (CVE-2026-14641)
1 rule 1 TTP 1 CVEA critical vulnerability, CVE-2026-14641, in SourceCodester Class and Exam Timetabling System version 1.0 allows for remote SQL injection via the 'ID' argument in the '/edit_course.php' file, enabling unauthenticated attackers to manipulate database queries with a publicly disclosed exploit.
SourceCodester SEO Meta Tag Extractor 1.0 - Server-Side Request Forgery (SSRF) - CVE-2026-10287
2 rules 1 TTP 1 CVESourceCodester SEO Meta Tag Extractor 1.0 is vulnerable to server-side request forgery (SSRF) via manipulation of the 'url' argument in the get_headers function of the /index.php file, potentially allowing a remote attacker to make requests to internal or external systems.
SourceCodester Simple POS and Inventory System SQL Injection Vulnerability (CVE-2026-9447)
2 rules 1 TTP 1 CVEA SQL injection vulnerability (CVE-2026-9447) exists in SourceCodester Simple POS and Inventory System 1.0, allowing remote attackers to execute arbitrary SQL commands by manipulating the 'Name' argument in the /user/search.php file.
CVE-2026-9356: SourceCodester Hospitals Patient Records Management System SQL Injection
2 rules 1 TTPA SQL injection vulnerability exists in SourceCodester Hospitals Patient Records Management System 1.0 within the /admin/patients/manage_history.php file, where manipulation of the ID argument can lead to remote exploitation.
SourceCodester Hospitals Patient Records Management System SQL Injection Vulnerability (CVE-2026-9355)
2 rules 1 TTP 1 CVESourceCodester Hospitals Patient Records Management System version 1.0 is vulnerable to SQL injection (CVE-2026-9355) via the ID parameter in the /classes/Master.php?f=save_patient_history endpoint, allowing a remote attacker to execute arbitrary SQL queries.
SourceCodester SUP Online Shopping SQL Injection Vulnerability (CVE-2026-8130)
2 rules 1 TTP 1 CVESourceCodester SUP Online Shopping 1.0 is vulnerable to SQL injection via the 'seenid' parameter in /admin/message.php, allowing remote attackers to execute arbitrary SQL commands; exploit code is publicly available.
SourceCodester SUP Online Shopping 1.0 SQL Injection Vulnerability
2 rules 1 TTP 1 CVESourceCodester SUP Online Shopping 1.0 is vulnerable to SQL injection via the msgid parameter in /admin/replymsg.php, allowing remote attackers to execute arbitrary SQL commands.
SourceCodester Comment System 1.0 SQL Injection Vulnerability (CVE-2026-8126)
2 rules 1 TTP 1 CVEA SQL injection vulnerability exists in SourceCodester Comment System 1.0, specifically affecting the post_comment.php file; by manipulating the 'Name' argument, remote attackers can inject SQL code, potentially leading to unauthorized access or data modification.
SourceCodester Pharmacy Sales and Inventory System SQL Injection Vulnerability
2 rules 1 TTP 1 CVEA remote SQL injection vulnerability exists in SourceCodester Pharmacy Sales and Inventory System 1.0 via manipulation of the ID argument in the /ajax.php?action=save_user file, potentially allowing attackers to execute arbitrary SQL queries.
SourceCodester Pharmacy Sales and Inventory System SQL Injection Vulnerability
2 rules 1 TTP 1 CVECVE-2026-7550 is an SQL injection vulnerability in SourceCodester Pharmacy Sales and Inventory System 1.0, allowing remote attackers to execute arbitrary SQL commands by manipulating the ID argument in the /ajax.php?action=save_customer endpoint.
SourceCodester Advanced School Management System SQL Injection Vulnerability
2 rules 1 TTP 1 CVEA SQL injection vulnerability (CVE-2026-7545) exists in SourceCodester Advanced School Management System 1.0 within the checkEmail endpoint of commonController.php, allowing remote attackers to potentially execute arbitrary SQL commands.
SourceCodester Pharmacy Sales and Inventory System SQL Injection Vulnerability
2 rules 1 TTP 1 CVEA remote SQL injection vulnerability exists in SourceCodester Pharmacy Sales and Inventory System 1.0 via manipulation of the ID parameter in the /ajax.php?action=delete_category endpoint, potentially leading to unauthorized data access or modification.
SourceCodester Pharmacy Sales and Inventory System SQL Injection Vulnerability (CVE-2026-7199)
2 rules 1 TTP 1 CVEA SQL injection vulnerability (CVE-2026-7199) exists in SourceCodester Pharmacy Sales and Inventory System 1.0, allowing remote attackers to execute arbitrary SQL commands by manipulating the 'ID' parameter in the `/ajax.php?action=delete_product` endpoint, potentially leading to data breach or system compromise.
SourceCodester Pharmacy Sales and Inventory System SQL Injection Vulnerability
2 rules 1 TTP 1 CVESourceCodester Pharmacy Sales and Inventory System 1.0 is vulnerable to SQL injection by manipulating the ID argument in the /ajax.php?action=save_receiving file, allowing remote attackers to execute arbitrary SQL commands.
SourceCodester Hotel Management System SQL Injection Vulnerability
2 rules 1 TTP 1 CVEA SQL injection vulnerability exists in SourceCodester Hotel Management System 1.0 in the /index.php/reservation/check component due to improper sanitization of the room_type parameter, allowing a remote attacker to execute arbitrary SQL commands.
SourceCodester Patients Waiting Area Queue Management System Improper Authorization Vulnerability
2 rules 1 TTP 6 IOCsA remote, unauthenticated attacker can bypass authorization in SourceCodester Patients Waiting Area Queue Management System 1.0 by manipulating the ValidateToken function in the Patient Check-In Module.
SourceCodester Food Ordering System SQL Injection Vulnerability (CVE-2026-4839)
2 rules 1 TTPCVE-2026-4839 is a SQL injection vulnerability in the SourceCodester Food Ordering System 1.0, affecting the /purchase.php file and allowing remote attackers to manipulate the 'custom' argument to inject malicious SQL code.
SourceCodester Pharmacy Sales and Inventory System SQL Injection Vulnerability
2 rules 1 TTP 1 CVECVE-2026-6187 is a remote SQL injection vulnerability in SourceCodester Pharmacy Sales and Inventory System 1.0 via the ID parameter in /ajax.php?action=chk_prod_availability, allowing unauthenticated attackers to execute arbitrary SQL queries.