cbcvebase.

Sourcecodester Multi-Vendor Online Grocery Management System vulnerabilities

6 known vulnerabilities affecting sourcecodester/multi-vendor_online_grocery_management_system.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2026-14690P3HIGHCVSS 7.3v1.02026-07-05
CVE-2026-14690 [HIGH] CWE-266 CVE-2026-14690: A weakness has been identified in SourceCodester Multi-Vendor Online Grocery Management System 1.0. A weakness has been identified in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This affects the function save_users of the file classes/Users.php. This manipulation causes improper authorization. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
nvd
CVE-2026-14695P3HIGHCVSS 7.3v1.02026-07-05
CVE-2026-14695 [HIGH] CWE-74 CVE-2026-14695: A vulnerability was found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This A vulnerability was found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This affects the function save_client of the file classes/Users.php of the component Registration Handler. The manipulation of the argument Name results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could
nvd
CVE-2026-14691P3MEDIUMCVSS 6.3v1.02026-07-05
CVE-2026-14691 [MEDIUM] CWE-74 CVE-2026-14691: A security vulnerability has been detected in SourceCodester Multi-Vendor Online Grocery Management A security vulnerability has been detected in SourceCodester Multi-Vendor Online Grocery Management System 1.0. This impacts the function update_settings_info of the file classes/SystemSettings.php of the component Setting Handler. Such manipulation of the argument content[] leads to code injection. The attack can be executed remotely. The exploit has
nvd
CVE-2026-14692P3MEDIUMCVSS 6.3v1.0v5.7.262026-07-05
CVE-2026-14692 [MEDIUM] CWE-74 CVE-2026-14692: A vulnerability was detected in SourceCodester Multi-Vendor Online Grocery Management System 1.0/5.7 A vulnerability was detected in SourceCodester Multi-Vendor Online Grocery Management System 1.0/5.7.26. Affected is the function save_shop_type of the file classes/Master.php of the component POST Parameter Handler. Performing a manipulation results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and ma
nvd
CVE-2026-14694P3MEDIUMCVSS 6.3v1.02026-07-05
CVE-2026-14694 [MEDIUM] CWE-74 CVE-2026-14694: A vulnerability has been found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. A vulnerability has been found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. Affected by this issue is the function cancel_order of the file classes/Master.php of the component POST Parameter Handler. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been
nvd
CVE-2026-14693P4MEDIUMCVSS 5.4v1.02026-07-05
CVE-2026-14693 [MEDIUM] CWE-266 CVE-2026-14693: A flaw has been found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. Affected A flaw has been found in SourceCodester Multi-Vendor Online Grocery Management System 1.0. Affected by this vulnerability is the function cancel_order of the file classes/Master.php. Executing a manipulation can lead to improper authorization. The attack may be performed from remote. The exploit has been published and may be used.
nvd
Sourcecodester Multi-Vendor Online Grocery Management System vulnerabilities | cvebase