Security Advisory
CVE-2025-26156
8.8
HIGH
Vulnerability Description
A SQL Injection vulnerability was found in /shopping/track-orders.php in PHPGurukul Online Shopping Portal v2.1, which allows remote attackers to execute arbitrary code via orderid POST request parameter.
Published Date
February 14, 2025
Official Source
NIST NVD Advisory