CVE-2025-51626: Xiaoliuchu Pss.sale.com

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

SQL injection vulnerability in pss.sale.com 1.0 via the id parameter to the userfiles/php/cancel_order.php endpoint.

Affected products

Published 2026-01-09. Last modified 2026-06-17.