CVE-2026-85643: Code-Projects Online Shopping System

Medium severity, CVSS 4.7. EPSS: 0.3% chance of exploitation in the next 30 days.

A flaw has been found in code-projects Online Shopping System 1.0. Impacted is the function mysqli_query of the file admin/adduser.php. Executing a manipulation of the argument mobile can lead to sql injection. The attack may be performed from remote. The exploit has been published and may be used.

Affected products

Published 2026-09-04. Last modified 2026-09-08.