CVE-2026-10559: fallo de gravedad media en SourceCodester Pizzafy Ecommerce System
SourceCodester Pizzafy Ecommerce System index.php file inclusion
Publicada el
33Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 5.3epss 0.2%
probabilidad de explotación
0.2%top 88% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is an unknown function of the file /index.php. Executing a manipulation of the argument page can lead to file inclusion. The attack may be performed from remote. The exploit has been published and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
SourceCodester · Pizzafy Ecommerce SystemPoCs públicas encontradas — 1
cve_referencegithub.com/cyber-bhaskar10/CVE-Writeups/blob/main/CVE%20Writeup%20LFI%20via%20Null%20Byte%20Injection%20in%20index.php.mdno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
CVEs relacionadas — SourceCodester Pizzafy Ecommerce System
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-8117MEDIUMSourceCodester Pizzafy Ecommerce System index.php cross site scriptingEPSS 0.4%CVE-2026-7228MEDIUMSourceCodester Pizzafy Ecommerce System ajax.php get_cart_count sql injectionEPSS 0.4%CVE-2026-7227MEDIUMSourceCodester Pizzafy Ecommerce System ajax.php login sql injectionEPSS 0.4%CVE-2026-7226MEDIUMSourceCodester Pizzafy Ecommerce System ajax.php login2 sql injectionEPSS 0.4%CVE-2026-7225MEDIUMSourceCodester Pizzafy Ecommerce System ajax.php delete_menu sql injectionEPSS 0.4%CVE-2026-7224MEDIUMSourceCodester Pizzafy Ecommerce System ajax.php delete_cart sql injectionEPSS 0.4%
Referencias
https://github.com/cyber-bhaskar10/CVE-Writeups/blob/main/CVE%20Writeup%20LFI%20via%20Null%20Byte%20Injection%20in%20index.php.mdhttps://vuldb.com/cve/CVE-2026-10559https://vuldb.com/submit/828822https://vuldb.com/vuln/367649https://vuldb.com/vuln/367649/ctihttps://www.sourcecodester.com/