CVE-2026-82701
published 2026-08-31CVE-2026-82701: A vulnerability was determined in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /action.php of the…
PriorityP344high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.26%
18.1th percentile
A vulnerability was determined in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /action.php of the component Search Functionality. This manipulation of the argument keyword causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| code-projects | online_shopping_system | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv4.05.5MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A vulnerability was determined in code-projects Online Shopping System 1.0.
ghsa_unreviewed·2026-08-31
CVE-2026-82701 [MEDIUM] CWE-74 A vulnerability was determined in code-projects Online Shopping System 1.0.
A vulnerability was determined in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /action.php of the component Search Functionality. This manipulation of the argument keyword causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
VulDB
code-projects Online Shopping System 1.0 Search Functionality /action.php keyword sql injection
vuldb·2026-08-30
CVE-2026-82701 [CRITICAL] code-projects Online Shopping System 1.0 Search Functionality /action.php keyword sql injection
A vulnerability identified as critical has been detected in code-projects Online Shopping System 1.0. Affected by this issue is some unknown functionality of the file /action.php of the component Search Functionality. This manipulation of the argument keyword causes sql injection.
The identification of this vulnerability is CVE-2026-82701. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://code-projects.org/https://github.com/ahmadmarz10-hub/CVEsMarz/blob/main/Time-Based%20Blind%20SQL%20Injection%20in%20Online%20Shopping%20System%20%60keyword%60%20Parameter.mdhttps://vuldb.com/cve/CVE-2026-82701https://vuldb.com/submit/894396https://vuldb.com/vuln/397190https://vuldb.com/vuln/397190/cti
2026-08-31
Published