CVE-2026-7297

· NIST NVD ↗

A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. This vulnerability affects the function save_user of the file /admin/ajax.php?action=save_user. Executing a manipulation of the argument Name can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

LOW
CVSS severity
2.4
CVSS base score
2026-04-28
Published

CWE codes

CWE-79CWE-94

Sources