VYPR

Pizzafy Ecommerce System

by Sourcecodester

CVEs (27)

  • CVE-2026-8117MedMay 8, 2026
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issue affects some unknown processing of the file /admin/index.php. Such manipulation of the argument page leads to cross site scripting. The attack may be launched remotely. The…

  • CVE-2026-7297LowApr 28, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation of the argument Name can lead to cross site scripting. The attack can be…

  • CVE-2026-7296LowApr 28, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_order of the file /admin/ajax.php?action=save_order. Performing a manipulation of the argument first_name results in cross site scripting. Remote exploitation of the attack…

  • CVE-2026-7295LowApr 28, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu. Such manipulation of the argument Name leads to cross site scripting. The attack may be launched…

  • CVE-2026-7294LowApr 28, 2026
    risk 0.16cvss 2.4epss 0.00

    A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /admin/index.php?page=save_settings. This manipulation of the argument Name causes cross site scripting. The attack may be initiated…

  • CVE-2026-16226MedJul 19, 2026
    risk 0.00cvss 4.7epss 0.00

    A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack is possible to be carried out remotely.

  • CVE-2026-14713HigJul 5, 2026
    risk 0.00cvss 7.3epss 0.00

    A security flaw has been discovered in SourceCodester Pizzafy E-Commerce System 1.0. This vulnerability affects unknown code of the file /admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The…

Page 2 of 2