CVE-2026-22242Medium· 4.9▾ SunlitCoreShop is a Pimcore enhanced eCommerce solution. Prior to version 4.1.8, a blind SQL injection vulnerability exists in the application that allows an authenticated administrator-level user to extract database contents using boolean-bas…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
CoreShop is a Pimcore enhanced eCommerce solution. Prior to version 4.1.8, a blind SQL injection vulnerability exists in the application that allows an authenticated administrator-level user to extract database contents using boolean-based or time-based techniques. The database account used by the application is read-only and non-DBA, limiting impact to confidential data disclosure only. No data modification or service disruption is possible. This issue has been patched in version 4.1.8.
coreshop < 4.1.8Upgrade past the affected range:
coreshop 4.1.8Connected by shared product, vendor, weakness, or advisory.
CVE-2025-13263Medium· 6.3A vulnerability was identified in SourceCodester Online Magazine Management System 1.0
CVE-2025-11611Medium· 6.3A weakness has been identified in SourceCodester Simple Inventory System 1.0
CVE-2025-10079High· 7.3A flaw has been found in PHPGurukul Small CRM 4.0
CVE-2025-13567Medium· 6.3A vulnerability was detected in itsourcecode COVID Tracking System 1.0
CVE-2025-13289Medium· 6.3A vulnerability was detected in 1000projects Design & Development of Student Database Management System 1.0
CVE-2025-13290Medium· 6.3A vulnerability has been found in code-projects Simple Food Ordering System 1.0