Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.9

SourceCodester Shopping Cart Script: Remote SQL Injection Risk

CVE-2026-3148
Summary

A vulnerability in the SourceCodester Simple and Nice Shopping Cart Script 1.0 allows attackers to manipulate data in a way that can compromise the security of the system. This could potentially happen when a user signs up for an account. To protect your site, update to a fixed version of the script or consider replacing it with a more secure alternative.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
haben-cs9 simple_and_nice_shopping_cart_script 1.0 –
Original title
A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /signup.php. This manipulation of the argument Username cause...
Original description
A vulnerability was determined in SourceCodester Simple and Nice Shopping Cart Script 1.0. This impacts an unknown function of the file /signup.php. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
nvd CVSS2.0 7.5
nvd CVSS3.1 9.8
nvd CVSS4.0 6.9
Vulnerability type
CWE-74 Injection
CWE-89 SQL Injection
Published: 25 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026