CVE-2026-19920: code-projects Online Shopping System action.php sql injection
Published Aug 15, 2026
·Updated
A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown function of the file /action.php. This manipulation of the argument proId causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
1 affected component
Code-projects Online Shopping System=1.0
Event History
Aug 15, 2026
CVE Published
via MITRE·11:45 PM
Data Sourced
via MITRE·11:45 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-19920?
CVE-2026-19920 has a medium severity score of 6.3.
2
What type of vulnerability is CVE-2026-19920?
CVE-2026-19920 is a SQL Injection vulnerability.
3
How do I fix CVE-2026-19920?
To fix CVE-2026-19920, validate and sanitize user inputs in the '/action.php' file, particularly the 'proId' argument.
4
Can CVE-2026-19920 be exploited remotely?
Yes, CVE-2026-19920 can be exploited remotely.
5
What software is affected by CVE-2026-19920?
CVE-2026-19920 affects Code-projects Online Shopping System version 1.0.