Sploitus

CVE-2026-7228

2 known exploits for CVE-2026-7228

A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is the function get_cart_count of the file /admin/ajax.php?action=get_cart_count. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

Affected products
Pizzafy Ecommerce System
CVSS 2.0
7.5 HIGH
CVSS 3.1
7.3 HIGH
EPSS
0.3% (17th percentile)
Weakness
CWE-74, CWE-89
NVD status
Deferred
Published
2026-04-28
CVE-2026-7228 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2026-7228

Proof-of-concept code and exploit modules indexed by Sploitus