CVE-2026-5558 is a medium-severity SQL injection vulnerability affecting PHPGurukul Online Shopping Portal Project versions up to 2.1. This flaw, located in the /pending-orders.php file, allows remote attackers to manipulate the 'ID' parameter. With a CVSS score of 6.3, it has low attack complexity and could lead to limited compromise of confidentiality, integrity, and availability. An exploit for this vulnerability has been publicly published, and it is listed on a "Hot List" indicating active concern, though not yet in CISA's KEV catalog. Community discussions confirm awareness of this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| PHPGurukul | PHPGurukul Online Shopping Portal Project | 2.0, 2.1CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.