puneethreddyhc has 4 CVEs on record. The median CVSS is 6.5 (medium). The most common weakness class is CWE-89 (4).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Weakness classes
Products
- online_shopping_system_advanced 4
Worst active — by depth score
CVE-2025-51972Medium· 6.5A SQL Injection vulnerability exists in the login.php of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter.36CVE-2025-51969Medium· 6.5A SQL Injection vulnerability exists in the product.php page of PuneethReddyHC Online Shopping System Advanced 1.036CVE-2025-51968Medium· 6.5A SQL Injection vulnerability exists in the action.php file of PuneethReddyHC Online Shopping System Advanced 1.036CVE-2025-51971Medium· 5.4A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Advanced 1.030
puneethreddyhc vulnerabilities
CVEs affecting puneethreddyhc, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2025-51972Medium· 6.5A SQL Injection vulnerability exists in the login.php of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter.
A SQL Injection vulnerability exists in the login.php of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST parameter.
CVE-2025-51971Medium· 5.4A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Advanced 1.0
A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Advanced 1.0. Unsanitized user input in the f_name parameter is reflected in the server response without proper HTML enc…
CVE-2025-51969Medium· 6.5A SQL Injection vulnerability exists in the product.php page of PuneethReddyHC Online Shopping System Advanced 1.0
A SQL Injection vulnerability exists in the product.php page of PuneethReddyHC Online Shopping System Advanced 1.0. This flaw is present in the product_id GET parameter, which is not properly validated before being included in a SQL stat…
CVE-2025-51968Medium· 6.5A SQL Injection vulnerability exists in the action.php file of PuneethReddyHC Online Shopping System Advanced 1.0
A SQL Injection vulnerability exists in the action.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The application fails to properly sanitize user-supplied input in the proId POST parameter, allowing attackers to inject a…