CVE-2026-18592: osCommerce Email Template Configuration EmailController.php EmailController sql injection
A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of the file app/lib/backend/controllers/EmailController.php of the component Email Template Configuration. Performing a manipulation of the argument emailtemplateskey results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18592?
CVE-2026-18592 has a medium severity rating of 4.7.
How do I fix CVE-2026-18592?
To mitigate CVE-2026-18592, validate and sanitize user input in the EmailController function to prevent SQL injection.
What type of vulnerability is CVE-2026-18592?
CVE-2026-18592 is classified as a SQL Injection vulnerability.
What software is affected by CVE-2026-18592?
CVE-2026-18592 affects the osCommerce Email Template Configuration component.
When was CVE-2026-18592 published?
CVE-2026-18592 was published on August 3, 2026.