📦 Online Shopping Portal

by Phpgurukul

🔍 What is Online Shopping Portal?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-44659

CRITICAL CVSS 9.8 Nov 17, 2025

PHPGurukul Online Shopping Portal 2.0 contains a SQL injection vulnerability in the forgot-password.php page's email parameter. This allows attackers to execute arbitrary SQL commands on the database....

CVE-2025-57148

CRITICAL CVSS 9.1 Sep 3, 2025

phpgurukul Online Shopping Portal 2.0 contains an arbitrary file upload vulnerability in the admin product upload functionality. Attackers can upload malicious files like webshells to gain remote code...

CVE-2021-46110

CRITICAL CVSS 9.8 Feb 18, 2022

Online Shopping Portal v3.1 contains time-based SQL injection vulnerabilities in the email and contactno parameters, allowing attackers to execute arbitrary SQL commands and potentially access sensiti...

CVE-2025-5079

HIGH CVSS 7.3 May 22, 2025

This CVE describes a SQL injection vulnerability in PHPGurukul/Campcodes Online Shopping Portal 1.0. Attackers can exploit the 'remark' parameter in /admin/updateorder.php to execute arbitrary SQL com...

CVE-2025-5078

HIGH CVSS 7.3 May 22, 2025

This SQL injection vulnerability in PHPGurukul/Campcodes Online Shopping Portal 1.0 allows attackers to manipulate database queries through the Category parameter in /admin/subcategory.php. Attackers ...

CVE-2023-38890

HIGH CVSS 8.8 Aug 18, 2023

CVE-2023-38890 is an unauthenticated SQL injection vulnerability in Online Shopping Portal Project 3.1 that allows attackers to execute arbitrary SQL commands via the login form. This enables unauthor...

CVE-2021-37807

HIGH CVSS 7.5 Oct 27, 2021

This SQL injection vulnerability in Online Shopping Portal 3.1 allows attackers to execute arbitrary SQL commands via the email parameter in the /check_availability.php endpoint. This affects all user...

CVE-2024-44661

MEDIUM CVSS 5.4 Nov 17, 2025

PHPGurukul Online Shopping Portal 2.0 contains a cross-site scripting vulnerability in the quantity parameter of my-cart.php. This allows attackers to inject malicious scripts that execute in users' b...

CVE-2024-44664

MEDIUM CVSS 6.5 Nov 17, 2025

PHPGurukul Online Shopping Portal 2.0 contains a SQL injection vulnerability in product-details.php that allows attackers to manipulate database queries via name, summary, review, quality, price, and ...

CVE-2024-44660

MEDIUM CVSS 6.5 Nov 17, 2025

PHPGurukul Online Shopping Portal 2.0 contains SQL injection vulnerabilities in the login.php page through the fullname, emailid, and contactno parameters. This allows attackers to execute arbitrary S...

CVE-2024-44662

MEDIUM CVSS 6.5 Nov 17, 2025

PHPGurukul Online Shopping Portal 2.0 contains a SQL injection vulnerability in the admin login page's username parameter. This allows attackers to execute arbitrary SQL commands, potentially compromi...

CVE-2024-44663

MEDIUM CVSS 6.5 Nov 17, 2025

PHPGurukul Online Shopping Portal 2.0 contains a SQL injection vulnerability in the product parameter of search-result.php. This allows attackers to execute arbitrary SQL commands on the database. Any...

CVE-2025-52074

MEDIUM CVSS 6.1 Sep 12, 2025

PHPGURUKUL Online Shopping Portal 2.1 contains a stored cross-site scripting vulnerability in the quantity parameter when adding products to cart. Attackers can inject malicious scripts that execute i...

CVE-2025-1855

MEDIUM CVSS 6.3 Mar 3, 2025

This critical SQL injection vulnerability in PHPGurukul Online Shopping Portal 2.1 allows remote attackers to execute arbitrary SQL commands via the product-details.php file. Attackers can potentially...

CVE-2024-39090

MEDIUM CVSS 6.1 Jul 18, 2024

This vulnerability in PHPGurukul Online Shopping Portal Project version 2.0 allows attackers to perform CSRF attacks that lead to stored XSS. When exploited, it enables execution of arbitrary JavaScri...