CVE-2026-14652Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown function of the file /admin/login.php of the component Admin Login. The manipulation of the argument Username results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-07-04); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-04: 2Mentions · 2026-07-06: 1Patch / Workaround · 2026-07-06: 1Technical Details · 2026-07-06: 107-0407-06
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-042
Disclosure1General1
2026-07-061
Patch1
Full discourse3 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-14652 #SQLi in #SourceCodester Simple #Shopping Cart. Unpatched. #CVSS 7.3. Attackers can exploit admin login via username param. Patch or update immediately. #CVEAlert #infosec #developers #sysadmin #git #github #gitlab #development #devsecops #devops https://www.valtersit.com/cve/CVE-2026-14652

    Post summary

    The tweet announces CVE-2026-14652, an SQL injection vulnerability in SourceCodester Simple Shopping Cart with CVSS 7.3, and urges administrators to patch or update immediately.

    00030478
    1.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-14652 A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown function of the file /admin/login.php of the component A… https://www.cve.org/CVERecord?id=CVE-2026-14652 ----- Traducción: CVE-2026-14652 Se … http://infoflow.cloud`

    Post summary

    The tweet simply announces CVE-2026-14652 affecting SourceCodester Simple and Nice Shopping Cart Script 1.0 without providing further technical details, exploitation, or remediation information.

    0000026
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-14652 A vulnerability was found in SourceCodester Simple and Nice Shopping Cart Script 1.0. This affects an unknown function of the file /admin/login.php of the component A… https://www.cve.org/CVERecord?id=CVE-2026-14652

    Post summary

    A new CVE (CVE-2026-14652) has been reported for SourceCodester Simple and Nice Shopping Cart Script 1.0, affecting an unspecified function in /admin/login.php, with no PoC, exploit, or patch details provided.

    00000796
    57.7K followersView on X

Explore more