Vendorsoretnom23online_food_ordering_systemall versions
Vulnerabilities

oretnom23 Online Food Ordering System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

29CVEs
CVE-2021-41644
Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters.
Published 2021-10-29 · Modified
9.8EPSS 0.025
CVE-2022-29650
Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food-search.php.
Published 2022-05-25 · Modified
9.8EPSS 0.013
CVE-2022-36759
Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /dishes.php?res_id=.
Published 2022-09-02 · Modified
9.8EPSS 0.011
CVE-2023-24646
An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code via a crafted PHP file.
Published 2023-02-13 · Modified
9.8EPSS 0.011
CVE-2023-30122
An arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online Food Ordering System v2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
Published 2023-05-05 · Modified
9.8EPSS 0.010
CVE-2023-0332
SourceCodester Online Food Ordering System manage_user.php sql injection
Published 2023-01-17 · Modified
9.8EPSS 0.009
CVE-2020-29297
Multiple SQL Injection vulnerabilities in tourist5 Online-food-ordering-system 1.0.
Published 2023-01-20 · Modified
9.8EPSS 0.008
CVE-2024-0247
CodeAstro Online Food Ordering System Admin Panel sql injection
Published 2024-01-05 · Modified
9.8EPSS 0.008
CVE-2023-1432
SourceCodester Online Food Ordering System POST Request access control
Published 2023-03-16 · Modified
9.8EPSS 0.006
CVE-2023-0257
SourceCodester Online Food Ordering System Menu Form unrestricted upload
Published 2023-01-12 · Modified
9.8EPSS 0.005
CVE-2025-2387
SourceCodester Online Food Ordering System ajax.php sql injection
Published 2025-03-17 · Analyzed
9.8EPSS 0.005
CVE-2023-0256
SourceCodester Online Food Ordering System Login Page sql injection
Published 2023-01-12 · Modified
9.8EPSS 0.005
CVE-2026-30530
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an attacker to inject malicious SQL commands.
Published 2026-03-27 · Analyzed
9.8EPSS 0.005
CVE-2026-30533
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter.
Published 2026-03-27 · Analyzed
9.8EPSS 0.004
CVE-2026-30532
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter.
Published 2026-03-27 · Analyzed
9.8EPSS 0.003
CVE-2026-30529
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_user action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an authenticated attacker to inject malicious SQL commands.
Published 2026-03-27 · Analyzed
8.8EPSS 0.004
CVE-2026-30531
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_category action). The application fails to properly sanitize user input supplied to the "name" parameter. This allows an authenticated attacker to inject malicious SQL commands.
Published 2026-03-27 · Analyzed
8.8EPSS 0.004
CVE-2026-30534
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via the "id" parameter.
Published 2026-03-27 · Analyzed
8.3EPSS 0.003
CVE-2023-24647
Food Ordering System v2.0 was discovered to contain a SQL injection vulnerability via the email parameter.
Published 2023-02-13 · Modified
7.5EPSS 0.007
CVE-2022-29651
An arbitrary file upload vulnerability in the Select Image function of Online Food Ordering System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
Published 2022-05-25 · Modified
7.2EPSS 0.015
CVE-2024-8604
SourceCodester Online Food Ordering System Create an Account Page index.php cross site scripting
Published 2024-09-09 · Analyzed
6.9EPSS 0.006
CVE-2023-27073
A Cross-Site Request Forgery (CSRF) in Online Food Ordering System v1.0 allows attackers to change user details and credentials via a crafted POST request.
Published 2023-03-14 · Modified
6.5EPSS 0.003
CVE-2023-24192
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in login.php.
Published 2023-02-06 · Modified
6.1EPSS 0.005
CVE-2023-24194
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in navbar.php.
Published 2023-02-06 · Modified
6.1EPSS 0.005
CVE-2023-24195
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in index.php.
Published 2023-02-06 · Modified
6.1EPSS 0.005
CVE-2023-24191
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in signup.php.
Published 2023-02-06 · Modified
6.1EPSS 0.005
CVE-2023-24197
Online Food Ordering System v2 was discovered to contain a SQL injection vulnerability via the id parameter at view_order.php.
Published 2023-02-06 · Modified
6.1EPSS 0.005
CVE-2023-0258
SourceCodester Online Food Ordering System Category List cross site scripting
Published 2023-01-12 · Modified
6.1EPSS 0.004
CVE-2026-30527
A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Category management module within the admin panel. The application fails to properly sanitize user input supplied to the "Category Name" field when creating or updating a category. When an administrator or user visits the Category list page (or any page where this category is rendered), the injected JavaScript executes immediately in their browser.
Published 2026-03-27 · Modified
5.4EPSS 0.002