CVE-2025-11596: Fabian E-Commerce Website

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability was determined in code-projects E-Commerce Website 1.0. The affected element is an unknown function of the file /pages/delete_order_details.php. Executing manipulation of the argument order_id can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

Affected products

  • Fabian E-Commerce Website: version 1.0 only

Published 2025-10-11. Last modified 2026-10-08.