CVE-2026-108826 | Zen Cart up to 2.2.2 PayPal IPN paypaldp.php zen_db_perform txn_id sql injection

SecurityVulns

A vulnerability has been found in Zen Cart up to 2.2.2 and classified as critical. This impacts the function zen_db_perform in the library includes/modules/payment/paypaldp.php of the component PayPal IPN Handler. Performing a manipulation of the argument txn_id results in sql injection.

This vulnerability is identified as CVE-2026-108826. The attack can be initiated remotely. Additionally, an exploit exists.

It is suggested to install a patch to address this issue.VulDB Recent EntriesRead More