CVE-2026-7228

HIGH

SourceCodester Pizzafy Ecommerce System ajax.php get_cart_count sql injection

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-7228. PoCs published by mikecostanzi.

AI-analyzed exploit summary The repository contains no exploit code, technical analysis, or proof-of-concept for CVE-2026-7228. It only provides links to external resources for setting up virtual environments and downloading software, including a PHP e-commerce system (Pizzafy), but no details about the vulnerability itself.

Description

A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function get_cart_count of the file /admin/ajax.php?action=get_cart_count. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

Exploits (1)

nomisec STUB
by mikecostanzi · poc
https://github.com/mikecostanzi/ricerca-tesi

The repository contains no exploit code, technical analysis, or proof-of-concept for CVE-2026-7228. It only provides links to external resources for setting up virtual environments and downloading software, including a PHP e-commerce system (Pizzafy), but no details about the vulnerability itself.

Classification
Stub 95%
Attack Type
Other
Complexity
N/a
Reliability
N/a
Target: Pizzafy E-Commerce System (unspecified version)
No auth needed
Prerequisites: Access to external download links for VirtualBox, Windows 11, Lubuntu, and Pizzafy E-Commerce System
mistral-large-3 · analyzed Jul 24, 2026 Full analysis →

References (5)

Core 5
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-359828 | SourceCodester Pizzafy Ecommerce System ajax.php get_cart_count sql injection
https://vuldb.com/vuln/359828
Signature, Permissions Required signature permissions-required
VDB-359828 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/359828/cti
Third Party Advisory third-party-advisory
Submit #802416 | SourceCodester Pizzafy Ecommerce System 1.0 SQL Injection
https://vuldb.com/submit/802416

Scores

CVSS v3 7.3
EPSS 0.0025
EPSS Percentile 17.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
SourceCodester/Pizzafy Ecommerce System 1.0
Published Apr 28, 2026
Tracked Since Apr 28, 2026