Record summary

CVE-2026-5558 has a selected CVSS score of 5.3 (medium).

Description

A flaw has been found in PHPGurukul PHPGurukul Online Shopping Portal Project up to 2.1. Impacted is an unknown function of the file /pending-orders.php of the component Parameter Handler. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 6, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

PHPGurukul Online Shopping Portal Project

Browse PHPGurukul / PHPGurukul Online Shopping Portal Project
CVE List2.0affected
2.1affected

References

6
VDB-355328 | PHPGurukul PHPGurukul Online Shopping Portal Project Parameter pending-orders.php sql injectionvdb entryTechnical description
https://vuldb.com/vuln/355328