CVE-2026-105226 | osCommerce osCommerce2 up to 2.3.4.1 Newsletter Management admin/newsletters.php include module code injection (Issue 676)
A vulnerability was found in osCommerce osCommerce2 up to 2.3.4.1. It has been rated as problematic. This vulnerability affects the function include of the file admin/newsletters.php of the component Newsletter Management. Performing a manipulation of the argument module results in code injection.
This vulnerability is reported as CVE-2026-105226. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More