CVE-2026-10558: falha de média gravidade em SourceCodester Pizzafy Ecommerce System
SourceCodester Pizzafy Ecommerce System index.php file inclusion
Publicada em
33Vexday Risk Score
Sem sinal de exploração. Ela tem prova de conceito pública.
ssvc Attendcvss 5.3epss 0.2%
probabilidade de exploração
0.2%top 88% das CVEs
exploração observada
nãonenhuma fonte reporta
1 exploit(s) público(s)
A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument page results in file inclusion. The attack is possible to be carried out remotely. The exploit is now public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Produtos afetados
SourceCodester · Pizzafy Ecommerce SystemPoCs públicas encontradas — 1
cve_referencegithub.com/cyber-bhaskar10/CVE-Writeups/blob/main/CVE%20Writeup%20Local%20File%20Inclusion%20(LFI)%20in%20index.php.mdnão verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
CVEs relacionadas — SourceCodester Pizzafy Ecommerce System
No mesmo produto, das mais perigosas para as menos.
CVE-2026-8117MEDIUMSourceCodester Pizzafy Ecommerce System index.php cross site scriptingEPSS 0.4%CVE-2026-7228MEDIUMSourceCodester Pizzafy Ecommerce System ajax.php get_cart_count sql injectionEPSS 0.4%CVE-2026-7227MEDIUMSourceCodester Pizzafy Ecommerce System ajax.php login sql injectionEPSS 0.4%CVE-2026-7226MEDIUMSourceCodester Pizzafy Ecommerce System ajax.php login2 sql injectionEPSS 0.4%CVE-2026-7225MEDIUMSourceCodester Pizzafy Ecommerce System ajax.php delete_menu sql injectionEPSS 0.4%CVE-2026-7224MEDIUMSourceCodester Pizzafy Ecommerce System ajax.php delete_cart sql injectionEPSS 0.4%