VendorsPHPGurukulonline_shopping_portal2.1
Vulnerabilities

PHPGurukul Online Shopping Portal 2.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2025-1855
PHPGurukul Online Shopping Portal product-details.php sql injection
Published 2025-03-03 · Analyzed
8.8EPSS 0.005
CVE-2025-1578
PHPGurukul/Campcodes Online Shopping Portal search-result.php sql injection
Published 2025-02-23 · Modified
7.5EPSS 0.004
CVE-2025-52074
PHPGURUKUL Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) due to lack of input sanitization in the quantity parameter when adding a product to the cart.
Published 2025-09-12 · Analyzed
6.1EPSS 0.002
CVE-2025-57576
PHPGurukul Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) in /admin/updateorder.php.
Published 2025-09-04 · Analyzed
5.4EPSS 0.002
CVE-2025-65647
Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter.
Published 2025-11-25 · Analyzed
4.3EPSS 0.002