VendorsPuneethReddyHConline_shopping_system_advancedall versions
Vulnerabilities

PuneethReddyHC Online Shopping System Advanced

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2024-58316
Online Shopping System Advanced 1.0 SQL Injection via Payment Success Parameter
Published 2025-12-12 · Analyzed
8.7EPSS 0.006
CVE-2025-51970
A SQL Injection vulnerability exists in the action.php endpoint of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter.
Published 2025-07-29 · Analyzed
7.7EPSS 0.002
CVE-2025-51968
A SQL Injection vulnerability exists in the action.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The application fails to properly sanitize user-supplied input in the proId POST parameter, allowing attackers to inject arbitrary SQL expressions.
Published 2025-08-28 · Analyzed
6.5EPSS 0.002
CVE-2025-51969
A SQL Injection vulnerability exists in the product.php page of PuneethReddyHC Online Shopping System Advanced 1.0. This flaw is present in the product_id GET parameter, which is not properly validated before being included in a SQL statement.
Published 2025-08-28 · Analyzed
6.5EPSS 0.002
CVE-2025-51972
A SQL Injection vulnerability exists in the login.php of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter.
Published 2025-08-28 · Analyzed
6.5EPSS 0.002
CVE-2025-51971
A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Advanced 1.0. Unsanitized user input in the f_name parameter is reflected in the server response without proper HTML encoding or output escaping. This allows remote attackers to inject arbitrary JavaScript code.
Published 2025-08-28 · Analyzed
5.4EPSS 0.003