CVE-2026-14652
published 2026-07-04CVE-2026-14652: A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown function of the file /admin/login.php of the…
PriorityP344high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.41%
33.3th percentile
A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown function of the file /admin/login.php of the component Admin Login. The manipulation of the argument Username results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sourcecodester | simple_and_nice_shopping_cart_script | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0.
ghsa_unreviewed·2026-07-04
CVE-2026-14652 [MEDIUM] CWE-74 A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0.
A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown function of the file /admin/login.php of the component Admin Login. The manipulation of the argument Username results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.
VulDB
SourceCodester Simple and Nice Shopping Cart Script 1.0 Admin Login /admin/login.php Username sql injection
vuldb·2026-07-03
CVE-2026-14652 [CRITICAL] SourceCodester Simple and Nice Shopping Cart Script 1.0 Admin Login /admin/login.php Username sql injection
A vulnerability described as critical has been identified in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown function of the file /admin/login.php of the component Admin Login. The manipulation of the argument Username results in sql injection.
This vulnerability is cataloged as CVE-2026-14652. The attack may be launched remotely. Furthermore, there is an exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-04
Published