PT-2026-55720 · Kirilkirkov · Ecommerce-Codeigniter-Bootstrap

·

CVE-2026-14637

·

Published

2026-07-04

·

Updated

2026-07-06

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions kirilkirkov Ecommerce-CodeIgniter-Bootstrap versions up to 13fd582aaf49aeab7438acc0fc3eb973a1f5e6a7
Description A remote attack can be initiated through the manipulation of the shopping cart argument in the getCartItems() function within the application/libraries/ShoppingCart.php library. This manipulation leads to deserialization, a process where data is converted back into an object, which can be exploited to execute unauthorized code.
Recommendations Apply patch 49b20f53de2b7ec34e920b11c863f1491d911a04 to resolve the issue.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14637

Affected Products

Ecommerce-Codeigniter-Bootstrap