CVE-2026-16226 MEDIUM

CVE-2026-16226: SourceCodester Pizzafy Ecommerce System admin_class_novo.php save_settings unrestricted upload

Vendor Sourcecodester
Product Pizzafy Ecommerce System
Weakness CWE-434 · Unrestricted file upload
Published July 19, 2026
Last update July 20, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X

What the vulnerability does

01Description

A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack is possible to be carried out remotely.

Key dates

02Disclosure timeline

July 19, 2026 CVE published
July 20, 2026 Record updated

Related vulnerabilities

04Related CVE