github.comexploitissue tracking
https://github.com/f1rstb100d/CVE/issues/10 CVE-2026-5552
MEDIUM
PHPGurukul Online Shopping Portal Project Parameter sub-category.php sql injection
Record summary
CVE-2026-5552 has a selected CVSS score of 5.3 (medium).
Description
A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This issue affects some unknown processing of the file /sub-category.php of the component Parameter Handler. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Online Shopping Portal ProjectBrowse PHPGurukul / Online Shopping Portal Project | CVE List | 2.1 | affected |
References
6nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-5552 phpgurukul.comproduct
https://phpgurukul.com/ Submit #782864 | PHPGurukul Online Shopping Portal Project 2.1 SQL InjectionThird-party advisory
https://vuldb.com/submit/782864 VDB-355316 | PHPGurukul Online Shopping Portal Project Parameter sub-category.php sql injectionvdb entryTechnical description
https://vuldb.com/vuln/355316 VDB-355316 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/vuln/355316/cti