SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-16226

MEDIUM · CVSS 4.7 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

The SourceCodester Pizzafy Ecommerce System 1.0 is vulnerable due to an unrestricted file upload flaw in the save_settings function of the admin_class_novo.php file, which can be exploited remotely by manipulating the img argument. This weakness could allow attackers to upload malicious files, potentially leading to further compromise of the system. Organizations using this ecommerce platform should prioritize addressing this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-16226
Severity
MEDIUM
CVSS
4.7
EPSS
0.22%

Original NVD Description

A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack is possible to be carried out remotely.