CVE-2026-0584CRITICAL 9.8EPSS p23.1%
CVE-2026-0584CVE-2026-0584
Description
A weakness has been identified in code-projects Online Product Reservation System 1.0. This issue affects some unknown processing of the file app/products/left_cart.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.32% probability of exploitation · percentile 23.1% · 2026-06-19T12:03:05Z |
| Published | 2026-01-05 |
| Last modified | 2026-04-29 |
Underlying weaknesses· 2
References
- https://code-projects.org/
- https://github.com/foeCat/CVE/blob/main/OnlineProductReservation_PHP/sqli_left_cart.php.md
- https://github.com/foeCat/CVE/blob/main/OnlineProductReservation_PHP/sqli_left_cart.php.md#poc
- https://vuldb.com/?ctiid.339476
- https://vuldb.com/?id.339476
- https://vuldb.com/?submit.731095
2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')cwe-74 | 0% | live |
| Weakness | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')cwe-89 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.