CVE-2026-5558: PHPGurukul PHPGurukul Online Shopping Portal Project Parameter pending-orders.php sql injection
Published Apr 5, 2026
·Updated
A flaw has been found in PHPGurukul PHPGurukul Online Shopping Portal Project up to 2.1. Impacted is an unknown function of the file /pending-orders.php of the component Parameter Handler. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Affected Software
1 affected component
Phpgurukul PHPGurukul Online Shopping Portal Project<=2.1
Event History
Apr 5, 2026
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Feb 13, 58282
Event
via FIRST·08:13 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-5558?
CVE-2026-5558 has a medium severity rating of 5.3.
2
How do I fix CVE-2026-5558?
To fix CVE-2026-5558, sanitize user inputs in the pending-orders.php file to prevent SQL injection.
3
What type of vulnerability is CVE-2026-5558?
CVE-2026-5558 is classified as an SQL Injection vulnerability.
4
Can CVE-2026-5558 be exploited remotely?
Yes, CVE-2026-5558 can be exploited remotely due to its nature as an SQL injection flaw.
5
Which software is affected by CVE-2026-5558?
CVE-2026-5558 affects the PHPGurukul Online Shopping Portal Project up to version 2.1.