SourceCodester has 62 CVEs on record. Disclosure cadence is accelerating: 62 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 62. The median CVSS is 7.3 (high). None have a confirmed exploitation report. The dominant weakness classes are CWE-74 (37) and CWE-89 (37). Most affected products: Class and Exam Timetabling System (11), Online Reviewer Management System (8), Drug Recommendation System (7).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.3
- Publish → KEV
- —
- Last 90 days
- 62 prev 0
Products
- Class and Exam Timetabling System 11
- Online Reviewer Management System 8
- Drug Recommendation System 7
- Syllabus-Aligned Learning Management & Examination System 7
- Online Voting System 5
- Inventory Management System 4
Worst active — by depth score
CVE-2026-95927High· 7.3A vulnerability was identified in SourceCodester Online Reviewer Management System 1.052CVE-2026-95926High· 7.3A vulnerability was determined in SourceCodester Online Reviewer Management System 1.052CVE-2026-95925High· 7.3A vulnerability was found in SourceCodester Online Reviewer Management System 1.052CVE-2026-94015High· 7.3A vulnerability was identified in SourceCodester Drug Recommendation System 1.052CVE-2026-93974High· 7.3A flaw has been found in SourceCodester Online Reviewer Management System 1.052
SourceCodester vulnerabilities
CVEs affecting SourceCodester, newest first. Open any entry for full detail, references, and exploit status.
62 CVEsRSS
CVE-2026-86160High· 7.3PoCA vulnerability has been found in SourceCodester Online Voting System 1.0
A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such manipulation of the argument ID leads to sql injection. The attack ma…
CVE-2026-86159High· 7.3PoCA flaw has been found in SourceCodester Online Voting System 1.0
A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. Th…