# SourceCodester vulnerabilities & exploitation

> As of 2026-10-05, Threadlinqs tracks 23 SourceCodester CVEs, 0 in the CISA Known Exploited Vulnerabilities catalog, linked to 0 tracked threat campaigns.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 23 SourceCodester CVEs published between 2026-07-15 and 2026-09-15. The busiest month was 2026-07 (14 new CVEs). None of them is listed in CISA KEV yet.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 23 of 23 tracked SourceCodester CVEs.

- [CVE-2026-14652](https://intel.threadlinqs.com/cve/CVE-2026-14652) — HIGH 7.3 · EPSS 0.4% · 2026-07-04
- [CVE-2026-14653](https://intel.threadlinqs.com/cve/CVE-2026-14653) — HIGH 7.3 · EPSS 0.4% · 2026-07-04
- [CVE-2026-14654](https://intel.threadlinqs.com/cve/CVE-2026-14654) — HIGH 7.3 · EPSS 0.4% · 2026-07-04
- [CVE-2026-16485](https://intel.threadlinqs.com/cve/CVE-2026-16485) — MEDIUM 4.3 · EPSS 0.3% · 2026-07-21
- [CVE-2026-16486](https://intel.threadlinqs.com/cve/CVE-2026-16486) — MEDIUM 4.3 · EPSS 0.3% · 2026-07-21
- [CVE-2026-75078](https://intel.threadlinqs.com/cve/CVE-2026-75078) — MEDIUM 4.3 · EPSS 0.3% · 2026-08-17
- [CVE-2026-14770](https://intel.threadlinqs.com/cve/CVE-2026-14770) — HIGH 7.3 · EPSS 0.3% · 2026-07-05
- [CVE-2026-14771](https://intel.threadlinqs.com/cve/CVE-2026-14771) — HIGH 7.3 · EPSS 0.3% · 2026-07-05
- [CVE-2026-14772](https://intel.threadlinqs.com/cve/CVE-2026-14772) — HIGH 7.3 · EPSS 0.3% · 2026-07-05
- [CVE-2026-16152](https://intel.threadlinqs.com/cve/CVE-2026-16152) — HIGH 7.3 · EPSS 0.3% · 2026-07-18
- [CVE-2026-86222](https://intel.threadlinqs.com/cve/CVE-2026-86222) — HIGH 7.3 · EPSS 0.3% · 2026-09-06
- [CVE-2026-86223](https://intel.threadlinqs.com/cve/CVE-2026-86223) — HIGH 7.3 · EPSS 0.3% · 2026-09-06
- [CVE-2026-86224](https://intel.threadlinqs.com/cve/CVE-2026-86224) — HIGH 7.3 · EPSS 0.3% · 2026-09-06
- [CVE-2026-16154](https://intel.threadlinqs.com/cve/CVE-2026-16154) — HIGH 7.3 · EPSS 0.3% · 2026-07-18
- [CVE-2026-81203](https://intel.threadlinqs.com/cve/CVE-2026-81203) — HIGH 7.3 · EPSS 0.3% · 2026-08-26
- [CVE-2026-86220](https://intel.threadlinqs.com/cve/CVE-2026-86220) — HIGH 7.3 · EPSS 0.3% · 2026-09-06
- [CVE-2026-86221](https://intel.threadlinqs.com/cve/CVE-2026-86221) — HIGH 7.3 · EPSS 0.3% · 2026-09-06
- [CVE-2026-86225](https://intel.threadlinqs.com/cve/CVE-2026-86225) — HIGH 7.3 · EPSS 0.3% · 2026-09-06
- [CVE-2026-14775](https://intel.threadlinqs.com/cve/CVE-2026-14775) — MEDIUM 6.3 · EPSS 0.2% · 2026-07-05
- [CVE-2026-14776](https://intel.threadlinqs.com/cve/CVE-2026-14776) — MEDIUM 6.3 · EPSS 0.2% · 2026-07-05
- [CVE-2026-16155](https://intel.threadlinqs.com/cve/CVE-2026-16155) — LOW 3.5 · EPSS 0.2% · 2026-07-18
- [CVE-2026-16156](https://intel.threadlinqs.com/cve/CVE-2026-16156) — LOW 3.5 · EPSS 0.2% · 2026-07-18
- [CVE-2026-75077](https://intel.threadlinqs.com/cve/CVE-2026-75077) — MEDIUM 4.3 · 2026-08-17

## Products affected

Threadlinqs normalises CPE and CNA product records across all 23 CVEs; 4 distinct SourceCodester products are affected. The most frequently affected:

- Class and Exam Timetabling System — 17 CVEs
- Simple and Nice Shopping Cart Script — 3 CVEs
- Onlne Examination & Learning Management System — 2 CVEs
- Simple Online Food Ordering System — 1 CVE

## Threat activity

No tracked threat campaign references SourceCodester products or CVEs yet. Vulnerability records are still monitored for exploitation and linked as campaigns are ingested.

## How to prioritise SourceCodester patching

This order follows the data Threadlinqs holds for SourceCodester, not a generic severity checklist:

- No SourceCodester CVE is in CISA KEV yet, so rank by exploit probability instead.
- Outside KEV, the highest EPSS scores are [CVE-2026-14652](https://intel.threadlinqs.com/cve/CVE-2026-14652) (0.4%), [CVE-2026-14653](https://intel.threadlinqs.com/cve/CVE-2026-14653) (0.4%), [CVE-2026-14654](https://intel.threadlinqs.com/cve/CVE-2026-14654) (0.4%).
- 0 CVEs score Critical and 15 High on CVSS v3 (maximum 7.3, average 6.4); sequence these after KEV and high-EPSS items.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/sourcecodester
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
