Vendorsoretnom23online_food_ordering_system1.0
Vulnerabilities

oretnom23 Online Food Ordering System 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2022-29650
Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food-search.php.
Published 2022-05-25 · Modified
9.8EPSS 0.013
CVE-2022-36759
Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /dishes.php?res_id=.
Published 2022-09-02 · Modified
9.8EPSS 0.011
CVE-2020-29297
Multiple SQL Injection vulnerabilities in tourist5 Online-food-ordering-system 1.0.
Published 2023-01-20 · Modified
9.8EPSS 0.008
CVE-2024-0247
CodeAstro Online Food Ordering System Admin Panel sql injection
Published 2024-01-05 · Modified
9.8EPSS 0.008
CVE-2026-30530
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an attacker to inject malicious SQL commands.
Published 2026-03-27 · Analyzed
9.8EPSS 0.005
CVE-2026-30533
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter.
Published 2026-03-27 · Analyzed
9.8EPSS 0.004
CVE-2026-30532
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter.
Published 2026-03-27 · Analyzed
9.8EPSS 0.003
CVE-2026-30529
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_user action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an authenticated attacker to inject malicious SQL commands.
Published 2026-03-27 · Analyzed
8.8EPSS 0.004
CVE-2026-30531
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_category action). The application fails to properly sanitize user input supplied to the "name" parameter. This allows an authenticated attacker to inject malicious SQL commands.
Published 2026-03-27 · Analyzed
8.8EPSS 0.004
CVE-2026-30534
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via the "id" parameter.
Published 2026-03-27 · Analyzed
8.3EPSS 0.003
CVE-2022-29651
An arbitrary file upload vulnerability in the Select Image function of Online Food Ordering System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
Published 2022-05-25 · Modified
7.2EPSS 0.015
CVE-2023-27073
A Cross-Site Request Forgery (CSRF) in Online Food Ordering System v1.0 allows attackers to change user details and credentials via a crafted POST request.
Published 2023-03-14 · Modified
6.5EPSS 0.003
CVE-2026-30527
A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Category management module within the admin panel. The application fails to properly sanitize user input supplied to the "Category Name" field when creating or updating a category. When an administrator or user visits the Category list page (or any page where this category is rendered), the injected JavaScript executes immediately in their browser.
Published 2026-03-27 · Modified
5.4EPSS 0.002