CVE-2026-16226

A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings of the file /admin/admin_class_novo.php. This manipulation of the argument img causes unrestricted upload. The attack is possible to be carried out remotely.
Configurations

No configuration.

History

20 Jul 2026, 14:16

Type Values Removed Values Added
References () https://vuldb.com/submit/858229 - () https://vuldb.com/submit/858229 -

19 Jul 2026, 09:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-19 09:17

Updated : 2026-07-20 14:16


NVD link : CVE-2026-16226

Mitre link : CVE-2026-16226

CVE.ORG link : CVE-2026-16226


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control

CWE-434

Unrestricted Upload of File with Dangerous Type