Skip to main content

CVE-2025-11070

7.3
HIGHCVSS v3.1 Base Score
0.05%
LOW RiskEPSS (14th percentile)

A vulnerability was identified in Projectworlds Online Shopping System 1.0. This affects an unknown part of the file /store/cart_add.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.

Published: 9/27/2025
Modified: 10/3/2025
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

7.3HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

EPSS Score (Exploitation Probability)

0.05%LOW Exploitation Risk
14th percentile

This vulnerability has a 0.05% probability of being exploited in the next 30 days, ranking higher than 14% of all scored CVEs.

Related Vulnerabilities