CVE-2026-14767: Codeastro Ecommerce Website

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A security flaw has been discovered in CodeAstro Ecommerce Website 1.0. This affects an unknown part of the file /ecommerce-website-php/customer/confirm.php of the component POST Parameter Handler. The manipulation of the argument invoice_no results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

Affected products

  • Codeastro Ecommerce Website: version 1.0 only

Published 2026-07-05. Last modified 2026-07-06.