CVE-2026-14639: Codeastro Ecommerce Website

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability has been found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /ecommerce-website-php/customer/my_account.php?edit_account. Such manipulation of the argument c_name leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Affected products

  • Codeastro Ecommerce Website: version 1.0 only

Published 2026-07-04. Last modified 2026-07-07.