CVE-2024-44659: Phpgurukul Online Shopping Portal

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.

Affected products

  • Phpgurukul Online Shopping Portal: version 2.0 only

Published 2025-11-17. Last modified 2026-09-28.