CVE-2026-5552 describes a SQL injection vulnerability in PHPGurukul Online Shopping Portal Project 2.1, affecting the /sub-category.php file through manipulation of the 'pid' argument. Rated as medium severity (CVSS 6.3), this flaw allows for remote exploitation with low attack complexity, potentially impacting confidentiality, integrity, and availability. An exploit has been publicly released, making it readily usable for attacks, and the CVE is currently on the Hot List, though community discussion remains low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| PHPGurukul | Online Shopping Portal Project | 2.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.