CVE Tools

Online Shopping Portal

45 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Online Shopping Portal, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Online Shopping Portal CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Online Shopping Portal CVEs per month
MonthCVEs
2024-102
2024-1111
2024-120
2025-010
2025-021
2025-031
2025-040
2025-0512
2025-060
2025-070
2025-080
2025-093
2025-100
2025-117
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 45 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical37%
  • High1636%
  • Medium1533%
  • Low1124%

Latest CVEs

The 15 most recently published vulnerabilities affecting Online Shopping Portal.

  1. CVE-2025-65647Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows information disclosure via the oid parameter.4.3
  2. CVE-2024-44660PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the fullname, emailid, and contactno parameters in login.php.6.5
  3. CVE-2024-44663PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php.6.5
  4. CVE-2024-44664PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and value parameters in product-details.php.6.5
  5. CVE-2024-44662PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page.6.5
  6. CVE-2024-44661PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart.php.5.4
  7. CVE-2024-44659PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.9.8
  8. CVE-2025-52074PHPGURUKUL Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) due to lack of input sanitization in the quantity parameter when adding a product to the cart.6.1
  9. CVE-2025-57576PHPGurukul Online Shopping Portal 2.1 is vulnerable to Cross Site Scripting (XSS) in /admin/updateorder.php.5.4
  10. CVE-2025-57148phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the lack of extension validation.9.1
  11. CVE-2025-5367PHPGurukul Online Shopping Portal Project category.php sql injection7.3
  12. CVE-2025-5079PHPGurukul/Campcodes Online Shopping Portal updateorder.php sql injection7.3
  13. CVE-2025-5078PHPGurukul/Campcodes Online Shopping Portal subcategory.php sql injection7.3
  14. CVE-2025-5077Campcodes Online Shopping Portal edit-subcategory.php sql injection7.3
  15. CVE-2025-5059Campcodes Online Shopping Portal edit-subcategory.php unrestricted upload4.7

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store