PT-2026-35814 · Sourcecodester · Pizzafy Ecommerce System

R3Du

·

Published

2026-04-28

·

Updated

2026-04-28

·

CVE-2026-7294

CVSS v3.1

2.4

Low

AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save settings of the file /admin/index.php?page=save settings. This manipulation of the argument Name causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7294

Affected Products

Pizzafy Ecommerce System