A SQL injection vulnerability has been identified in code-projects Online Shopping System version 1.0. The flaw exists in the /action.php file within the Search Functionality component, where manipulation of the 'keyword' argument enables time-based blind SQL injection attacks. The vulnerability can be exploited remotely without authentication, making it accessible to a wide range of threat actors. A public exploit has already been disclosed, increasing the risk of active exploitation. The vulnerability has been assigned CVE-2026-82701 and is tracked by NVD and VulDB. This type of injection vulnerability can allow attackers to extract, modify, or delete database contents. The affected software is a widely used open-source e-commerce project, potentially impacting numerous deployments.