cbcvebase.

Sourcecodester Pizzafy Ecommerce System vulnerabilities

25 known vulnerabilities affecting sourcecodester/pizzafy_ecommerce_system.

Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM16LOW4

Vulnerabilities

Page 1 of 2
CVE-2026-7224P3HIGHCVSS 7.3v1.02026-04-28
CVE-2026-7224 [HIGH] CWE-74 CVE-2026-7224: A security flaw has been discovered in SourceCodester Pizzafy Ecommerce System 1.0. This affects the A security flaw has been discovered in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function delete_cart of the file /admin/ajax.php?action=delete_cart. Performing a manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
nvd
CVE-2026-7225P3HIGHCVSS 7.3v1.02026-04-28
CVE-2026-7225 [HIGH] CWE-74 CVE-2026-7225: A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability af A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function delete_menu of the file /admin/ajax.php?action=delete_menu. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used f
nvd
CVE-2026-7226P3HIGHCVSS 7.3v1.02026-04-28
CVE-2026-7226 [HIGH] CWE-74 CVE-2026-7226: A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issu A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issue affects the function login2 of the file /admin/ajax.php?action=login2. The manipulation of the argument e-mail leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
nvd
CVE-2026-7227P3HIGHCVSS 7.3v1.02026-04-28
CVE-2026-7227 [HIGH] CWE-74 CVE-2026-7227: A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the functio A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function Login of the file /admin/ajax.php?action=login. The manipulation of the argument e-mail results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.
nvd
CVE-2026-7228P3HIGHCVSS 7.3v1.02026-04-28
CVE-2026-7228 [HIGH] CWE-74 CVE-2026-7228: A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the fu A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function get_cart_count of the file /admin/ajax.php?action=get_cart_count. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
nvd
CVE-2026-7410P3MEDIUMCVSS 6.3v1.02026-04-29
CVE-2026-7410 [MEDIUM] CWE-74 CVE-2026-7410: A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability af A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=add_to_cart. The manipulation of the argument pid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2026-7264P3MEDIUMCVSS 6.3v1.02026-04-28
CVE-2026-7264 [MEDIUM] CWE-74 CVE-2026-7264: A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the funct A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is the function get_cart_items of the file /admin/ajax.php?action=get_cart_items. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for atta
nvd
CVE-2026-7268P3MEDIUMCVSS 6.3v1.02026-04-28
CVE-2026-7268 [MEDIUM] CWE-74 CVE-2026-7268: A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This impacts the func A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. This impacts the function save_category of the file /admin/ajax.php?action=save_category. Such manipulation of the argument Name leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
nvd
CVE-2026-10558P3MEDIUMCVSS 6.3v1.02026-06-02
CVE-2026-10558 [MEDIUM] CWE-73 CVE-2026-10558: A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is an unknown A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument page results in file inclusion. The attack is possible to be carried out remotely. The exploit is now public and may be used.
nvd
CVE-2026-10559P3MEDIUMCVSS 6.3v1.02026-06-02
CVE-2026-10559 [MEDIUM] CWE-73 CVE-2026-10559: A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is an unk A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is an unknown function of the file /index.php. Executing a manipulation of the argument page can lead to file inclusion. The attack may be performed from remote. The exploit has been published and may be used.
nvd
CVE-2026-7266P3MEDIUMCVSS 6.3v1.02026-04-28
CVE-2026-7266 [MEDIUM] CWE-74 CVE-2026-7266: A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. The impacted element is A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. The impacted element is the function save_order of the file /admin/ajax.php?action=save_order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.
nvd
CVE-2026-7265P3MEDIUMCVSS 6.3v1.02026-04-28
CVE-2026-7265 [MEDIUM] CWE-74 CVE-2026-7265: A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. The affec A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function Category of the file pizza/index.php?page=category. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
nvd
CVE-2026-7267P3MEDIUMCVSS 6.3v1.02026-04-28
CVE-2026-7267 [MEDIUM] CWE-74 CVE-2026-7267: A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects an unknown functi A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects an unknown function of the file /view_prod.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
nvd
CVE-2026-7393P4MEDIUMCVSS 4.7v1.02026-04-29
CVE-2026-7393 [MEDIUM] CWE-284 CVE-2026-7393: A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function s A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file /admin/admin_class_novo.php of the component File Extension Handler. Performing a manipulation of the argument img results in unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made public a
nvd
CVE-2026-16226P4MEDIUMCVSS 4.7v1.02026-07-19
CVE-2026-16226 [MEDIUM] CWE-284 CVE-2026-16226: A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the func A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack is possible to be carried out remotely.
nvd
CVE-2026-7407P4MEDIUMCVSS 4.7v1.02026-04-29
CVE-2026-7407 [MEDIUM] CWE-74 CVE-2026-7407: A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /pizzafy/admin/ajax.php?action=save_settings of the component Setting Handler. Such manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been dis
nvd
CVE-2026-7293P4MEDIUMCVSS 4.7v1.02026-04-28
CVE-2026-7293 [MEDIUM] CWE-74 CVE-2026-7293: A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the functio A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function delete_category of the file /admin/ajax.php?action=delete_category. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.
nvd
CVE-2026-7408P4MEDIUMCVSS 4.7v1.02026-04-29
CVE-2026-7408 [MEDIUM] CWE-74 CVE-2026-7408: A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu. Performing a manipulation results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used.
nvd
CVE-2026-7394P4MEDIUMCVSS 4.7v1.02026-04-29
CVE-2026-7394 [MEDIUM] CWE-74 CVE-2026-7394: A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vuln A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/view_order.php of the component GET Parameter Handler. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly
nvd
CVE-2026-7409P4MEDIUMCVSS 4.7v1.02026-04-29
CVE-2026-7409 [MEDIUM] CWE-74 CVE-2026-7409: A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.
nvd
Sourcecodester Pizzafy Ecommerce System vulnerabilities | cvebase