PatchSiren

osCommerce CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW osCommerce CVE published 2026-10-05

CVE-2026-105226

A security flaw has been discovered in osCommerce osCommerce2 up to 2.3.4.1. This vulnerability affects the function include of the file admin/newsletters.php of the component Newsletter Management. Performing a manipulation of the argument module results in code injection. The attack is possible to be carried out remotely. Defenders responsible for osCommerce osCommerce2 installations, particularly those [truncated]

LOW osCommerce CVE published 2026-10-05

CVE-2026-105225

A vulnerability was identified in osCommerce osCommerce2 up to 2.3.4.1, affecting the function include of the file includes/classes/payment.php of the component Payment Page. Manipulation of the argument MODULE_PAYMENT_INSTALLED leads to code injection. The attack can be executed remotely. Defenders responsible for osCommerce osCommerce2 installations, especially those with publicly accessible payment pag [truncated]