github.comexploitissue tracking
https://github.com/f1rstb100d/CVE/issues/11 CVE-2026-5558
MEDIUM
PHPGurukul PHPGurukul Online Shopping Portal Project Parameter pending-orders.php sql injection
Record summary
CVE-2026-5558 has a selected CVSS score of 5.3 (medium).
Description
A flaw has been found in PHPGurukul PHPGurukul Online Shopping Portal Project up to 2.1. Impacted is an unknown function of the file /pending-orders.php of the component Parameter Handler. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
PHPGurukul Online Shopping Portal ProjectBrowse PHPGurukul / PHPGurukul Online Shopping Portal Project | CVE List | 2.0 | affected |
| 2.1 | affected |
References
6nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-5558 phpgurukul.comproduct
https://phpgurukul.com/ Submit #782877 | PHPGurukul Online Shopping Portal Project 2.1 SQL InjectionThird-party advisory
https://vuldb.com/submit/782877 VDB-355328 | PHPGurukul PHPGurukul Online Shopping Portal Project Parameter pending-orders.php sql injectionvdb entryTechnical description
https://vuldb.com/vuln/355328 VDB-355328 | CTI Indicators (IOB, IOC, TTP, IOA)signaturepermissions required
https://vuldb.com/vuln/355328/cti