Security Advisory

CVE-2025-26156

8.8
HIGH

Vulnerability Description

A SQL Injection vulnerability was found in /shopping/track-orders.php in PHPGurukul Online Shopping Portal v2.1, which allows remote attackers to execute arbitrary code via orderid POST request parameter.
Published Date February 14, 2025
Official Source NIST NVD Advisory