CVE-2026-5640: medium-severity vulnerability in PHPGurukul Online Shopping Portal Project
PHPGurukul Online Shopping Portal Project Parameter update-image2.php sql injection
Published
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.3epss 0.3%
exploitation probability
0.3%top 77% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /admin/update-image2.php of the component Parameter Handler. The manipulation of the argument filename leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
PHPGurukul · Online Shopping Portal Projectpublic PoCs found — 1
cve_referencegithub.com/f1rstb100d/CVE/issues/18unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — PHPGurukul Online Shopping Portal Project
In the same product, most dangerous first.
CVE-2025-5367MEDIUMPHPGurukul Online Shopping Portal Project category.php sql injectionEPSS 0.5%CVE-2025-9013MEDIUMPHPGurukul Online Shopping Portal Project password-recovery.php sql injectionEPSS 0.4%CVE-2025-9012MEDIUMPHPGurukul Online Shopping Portal Project bill-ship-addresses.php sql injectionEPSS 0.4%CVE-2025-9011MEDIUMPHPGurukul Online Shopping Portal Project signup.php sql injectionEPSS 0.4%CVE-2026-5641MEDIUMPHPGurukul Online Shopping Portal Project Parameter update-image1.php sql injectionEPSS 0.3%CVE-2026-5639MEDIUMPHPGurukul Online Shopping Portal Project Parameter update-image3.php sql injectionEPSS 0.3%