CVE-2026-7407
published 2026-04-29CVE-2026-7407: A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the…
PriorityP430medium4.7CVSS 3.1
AVNACLPRHUINSUCLILAL
EPSS
0.25%
16.6th percentile
A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /pizzafy/admin/ajax.php?action=save_settings of the component Setting Handler. Such manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sourcecodester | pizzafy_ecommerce_system | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
nvdv4.02.0LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.05.8MEDIUMAV:N/AC:L/Au:M/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mh74-f4h4-8h8r: A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1
ghsa_unreviewed·2026-04-29
CVE-2026-7407 [LOW] CWE-74 GHSA-mh74-f4h4-8h8r: A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1
A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /pizzafy/admin/ajax.php?action=save_settings of the component Setting Handler. Such manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
VulDB
SourceCodester Pizzafy Ecommerce System 1.0 Setting ajax.php?action=save_settings sql injection (EUVD-2026-26289)
vuldb·2026-04-29·CVSS 2.0
CVE-2026-7407 [LOW] SourceCodester Pizzafy Ecommerce System 1.0 Setting ajax.php?action=save_settings sql injection (EUVD-2026-26289)
A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0 and classified as critical. Affected by this vulnerability is the function save_settings of the file /pizzafy/admin/ajax.php?action=save_settings of the component Setting Handler. Such manipulation leads to sql injection.
This vulnerability is referenced as CVE-2026-7407. It is possible to launch the attack remotely. Furthermore, an exploit is available.
Suricata
ET WEB_SPECIFIC_APPS Netgear diag.cgi host_name Parameter Command Injection Attempt (CVE-2025-7407)
suricata·2026-01-26·CVSS 5.3
CVE-2025-7407 [MEDIUM] ET WEB_SPECIFIC_APPS Netgear diag.cgi host_name Parameter Command Injection Attempt (CVE-2025-7407)
ET WEB_SPECIFIC_APPS Netgear diag.cgi host_name Parameter Command Injection Attempt (CVE-2025-7407)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Netgear diag.cgi host_name Parameter Command Injection Attempt (CVE-2025-7407)"; flow:established,to_server; http.method; content:"POST"; http.uri; bsize:13; content:"/diag.cgi|3f|"; fast_pattern; http.request_body; content:"host_name|3d|"; pcre:"/^[^\x26]*?(?:(?:\x3b|%3[Bb])|(?:\x0a|%0[Aa])|(?:\x60|%60)|(?:\x7c|%7[Cc])|(?:\x24|%24))+/R"; reference:url,github.com/wudipjq/my_vuln/blob/main/Netgear7/vuln_66/66.md; reference:cve,2025-7407; classtype:attempted-admin; sid:2067092; rev:1; metadata:affected_product Netgear_Router, attack_target Networking_Equipment, tls_state plaintext, created_at 2026_01_26, cve CVE_2025_7407, d
No public exploits indexed.
No writeups or analysis indexed.
2026-04-29
Published