CVE-2026-105225

Source
https://cve.org/CVERecord?id=CVE-2026-105225
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105225.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105225
Published
2026-10-05T04:15:06Z
Modified
2026-10-08T02:30:48Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
osCommerce osCommerce2 Payment payment.php include code injection
Details

A vulnerability was identified in osCommerce osCommerce2 up to 2.3.4.1. This affects the function include of the file includes/classes/payment.php of the component Payment Page. Such manipulation of the argument MODULE_PAYMENT_INSTALLED leads to code injection. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-74",
        "CWE-94"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105225.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "2.3.4.0"
                },
                {
                    "last_affected": "2.3.4.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/oscommerce/oscommerce2

Affected ranges

Type
GIT
Repo
https://github.com/oscommerce/oscommerce2
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.3.4.1"
        },
        {
            "last_affected": "2.3.4.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

2.*
2.3.4.1
v2.*
v2.3.4.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105225.json"