CVE-2026-5640Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /admin/update-image2.php of the component Parameter Handler. The manipulation of the argument filename leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-06: 3Technical Details · 2026-04-06: 104-06
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5640 SQL Injection in PHPGurukul Online Shopping Portal Project 2.1 Parameter Handler https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5640

    Post summary

    The text announces a SQL Injection vulnerability in PHPGurukul Online Shopping Portal Project 2.1, providing basic technical details but no PoC, exploit, active exploitation notice, or patch information.

    0000047
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5640 A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /admin/update-image2.php of the… https://www.cve.org/CVERecord?id=CVE-2026-5640 ----- Traducción: CVE-2026-5640 Se … http://infoflow.cloud`

    Post summary

    CVE-2026-5640 has been identified in the PHPGurukul Online Shopping Portal Project 2.1, affecting an unknown function in /admin/update-image2.php, but no further technical details, patches, or exploitation information are provided.

    0000054
    67 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5640 A vulnerability has been found in PHPGurukul Online Shopping Portal Project 2.1. The affected element is an unknown function of the file /admin/update-image2.php of the… https://www.cve.org/CVERecord?id=CVE-2026-5640

    Post summary

    The post only notes the existence of a CVE with a minimal reference to a file path; no exploitation, mitigation, or technical detail provided.

    00000429
    57.0K followersView on X

Explore more