VendorsProjectworldsonline_shopping_system1.0
Vulnerabilities

Projectworlds Online Shopping System 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-43157
Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php.
Published 2021-12-22 · Modified
9.8EPSS 0.011
CVE-2025-11070
Projectworlds Online Shopping System cart_add.php sql injection
Published 2025-09-27 · Analyzed
9.8EPSS 0.005
CVE-2025-12215
projectworlds Online Shopping System login_submit.php sql injection
Published 2025-10-27 · Modified
9.8EPSS 0.004
CVE-2021-43158
In ProjectWorlds Online Shopping System PHP 1.0, a CSRF vulnerability in cart_remove.php allows a remote attacker to remove any product in the customer's cart.
Published 2021-12-22 · Modified
4.3EPSS 0.005