CVE-2026-85643
A flaw has been found in code-projects Online Shopping System 1.0. Impacted is the function mysqli_query of the file admin/adduser.php. Executing a manipulation of the argument mobile can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.
- Published Sep 4, 2026
- CVSS 2.0 low
- 0.3% chance of exploitation in the next 30 days (EPSS)