CVE-2023-38912: Superstorefinder PHP Script

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

SQL injection vulnerability in Super Store Finder PHP Script v.3.6 allows a remote attacker to execute arbitrary code via a crafted payload to the username parameter.

Affected products

Published 2023-09-14. Last modified 2026-06-17.