Online Ordering System
by Online Ordering System Project
CVEs (37)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-25211 | Cri | 0.64 | 9.8 | 0.02 | Jul 22, 2021 | Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, via the file upload to ordering\admin\products\edit.php. | ||
| CVE-2021-28294 | Cri | 0.64 | 9.8 | 0.04 | Mar 16, 2021 | Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE). | ||
| CVE-2021-28295 | Hig | 0.50 | 7.5 | 0.16 | Mar 16, 2021 | Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure. | ||
| CVE-2022-36581 | Hig | 0.49 | 7.5 | 0.01 | Aug 31, 2022 | Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /admin/login.php. | ||
| CVE-2022-36580 | Hig | 0.47 | 7.2 | 0.01 | Aug 31, 2022 | An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering System v2.3.2 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-30799 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php. | ||
| CVE-2022-30798 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php. | ||
| CVE-2022-30795 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php. | ||
| CVE-2022-30794 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php. | ||
| CVE-2023-27073 | Med | 0.42 | 6.5 | 0.00 | Mar 14, 2023 | A Cross-Site Request Forgery (CSRF) in Online Food Ordering System v1.0 allows attackers to change user details and credentials via a crafted POST request. | ||
| CVE-2025-7755 | Med | 0.41 | 6.3 | 0.00 | Jul 17, 2025 | A vulnerability was found in code-projects Online Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/edit_product.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated… | ||
| CVE-2023-27208 | Med | 0.40 | 6.1 | 0.00 | Mar 9, 2023 | A cross-site scripting (XSS) vulnerability in /php-opos/login.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the redirect parameter. | ||
| CVE-2023-24197 | Med | 0.40 | 6.1 | 0.00 | Feb 6, 2023 | Online Food Ordering System v2 was discovered to contain a SQL injection vulnerability via the id parameter at view_order.php. | ||
| CVE-2023-24195 | Med | 0.40 | 6.1 | 0.00 | Feb 6, 2023 | Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in index.php. | ||
| CVE-2023-24194 | Med | 0.40 | 6.1 | 0.00 | Feb 6, 2023 | Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in navbar.php. | ||
| CVE-2023-24192 | Med | 0.40 | 6.1 | 0.00 | Feb 6, 2023 | Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in login.php. | ||
| CVE-2023-24191 | Med | 0.40 | 6.1 | 0.00 | Feb 6, 2023 | Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in signup.php. |
- risk 0.64cvss 9.8epss 0.02
Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, via the file upload to ordering\admin\products\edit.php.
- risk 0.64cvss 9.8epss 0.04
Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE).
- risk 0.50cvss 7.5epss 0.16
Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure.
- risk 0.49cvss 7.5epss 0.01
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /admin/login.php.
- risk 0.47cvss 7.2epss 0.01
An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering System v2.3.2 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.47cvss 7.2epss 0.01
Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php.
- risk 0.47cvss 7.2epss 0.01
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php.
- risk 0.47cvss 7.2epss 0.01
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php.
- risk 0.47cvss 7.2epss 0.01
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php.
- risk 0.42cvss 6.5epss 0.00
A Cross-Site Request Forgery (CSRF) in Online Food Ordering System v1.0 allows attackers to change user details and credentials via a crafted POST request.
- risk 0.41cvss 6.3epss 0.00
A vulnerability was found in code-projects Online Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/edit_product.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated…
- risk 0.40cvss 6.1epss 0.00
A cross-site scripting (XSS) vulnerability in /php-opos/login.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the redirect parameter.
- risk 0.40cvss 6.1epss 0.00
Online Food Ordering System v2 was discovered to contain a SQL injection vulnerability via the id parameter at view_order.php.
- risk 0.40cvss 6.1epss 0.00
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in index.php.
- risk 0.40cvss 6.1epss 0.00
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in navbar.php.
- risk 0.40cvss 6.1epss 0.00
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in login.php.
- risk 0.40cvss 6.1epss 0.00
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in signup.php.
Page 2 of 2