๐Ÿ” CVE Alert

CVE-2026-18592

MEDIUM 4.7

osCommerce Email Template Configuration EmailController.php EmailController sql injection

CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th

A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of the file app/lib/backend/controllers/EmailController.php of the component Email Template Configuration. Performing a manipulation of the argument email_templates_key results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CWE CWE-89 CWE-74
Vendor n/a
Product oscommerce
Published Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for n/a oscommerce

Be the first to know when new medium vulnerabilities affecting n/a oscommerce are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

n/a / osCommerce
4.14.63493

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/385420 vuldb.com: https://vuldb.com/vuln/385420/cti vuldb.com: https://vuldb.com/cve/CVE-2026-18592 vuldb.com: https://vuldb.com/submit/851289 anonymous.4open.science: https://anonymous.4open.science/r/oscommerce-E7D5/second-order-sqli-report.md

Credits

๐Ÿ” 6dAksIAdf4bjuJIv8MWq (VulDB User) VulDB CNA Team