CVE-2026-105225 | osCommerce osCommerce2 up to 2.3.4.1 Payment Page payment.php include MODULE_PAYMENT_INSTALLED code injection (Issue 677)

SecurityVulns

A vulnerability was found in osCommerce osCommerce2 up to 2.3.4.1. It has been declared as problematic. This affects the function include of the file includes/classes/payment.php of the component Payment Page. Such manipulation of the argument MODULE_PAYMENT_INSTALLED leads to code injection.

This vulnerability is documented as CVE-2026-105225. The attack can be executed remotely. Additionally, an exploit exists.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More