#Ecommerce
All CosmicBytez Labs articles tagged #Ecommerce, across news, security advisories, how-to guides, and projects.
- Security
CVE-2025-65336: Critical SQL Injection in Fruits Bazar PHP Ecommerce
CVSS 9.8 SQL injection vulnerability in the show_price_by_pdtId.php endpoint of the Fruits Bazar PHP/MySQLi ecommerce project allows unauthenticated...
- Security
CVE-2026-14635: Unrestricted File Upload RCE in CodeIgniter Ecommerce Bootstrap
A high-severity unrestricted file upload vulnerability in the kirilkirkov Ecommerce-CodeIgniter-Bootstrap allows authenticated vendor users to upload...
- Security
CVE-2020-37168: Systempay Weak Crypto Allows Payment
A CVSS 9.8 vulnerability in Systempay 1.0 allows attackers to brute force a 16-character production secret key from intercepted POST data, enabling them...
- Security
CVE-2021-47923: OpenCart 3.0.3.8 Session Fixation Enables
OpenCart 3.0.3.8 fails to regenerate the OCSESSID session cookie after authentication, allowing attackers to inject a known session ID and hijack any user...
- Security
CVE-2026-7224: SQL Injection in Pizzafy Ecommerce System 1.0
A high-severity SQL injection vulnerability has been discovered in SourceCodester Pizzafy Ecommerce System 1.0, allowing remote attackers to manipulate...