VYPR

Online Food Ordering System

by Oretnom23

CVEs (44)

  • CVE-2026-30533CriMar 27, 2026
    risk 0.64cvss 9.8epss 0.00

    A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter.

  • CVE-2026-30532CriMar 27, 2026
    risk 0.64cvss 9.8epss 0.00

    A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter.

  • CVE-2026-30530CriMar 27, 2026
    risk 0.64cvss 9.8epss 0.00

    A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an attacker to inject…

  • CVE-2023-30122CriMay 5, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online Food Ordering System v2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2023-24646CriFeb 13, 2023
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code via a crafted PHP file.

  • CVE-2020-29297CriJan 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Multiple SQL Injection vulnerabilities in tourist5 Online-food-ordering-system 1.0.

  • CVE-2022-36759CriSep 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /dishes.php?res_id=.

  • CVE-2022-32336CriJun 14, 2022
    risk 0.64cvss 9.8epss 0.01

    Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/view_menu.php?id=.

  • CVE-2022-30797CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php.

  • CVE-2022-29650CriMay 25, 2022
    risk 0.64cvss 9.8epss 0.01

    Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food-search.php.

  • CVE-2021-41644CriOct 29, 2021
    risk 0.64cvss 9.8epss 0.02

    Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters.

  • CVE-2026-30531HigMar 27, 2026
    risk 0.57cvss 8.8epss 0.00

    A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_category action). The application fails to properly sanitize user input supplied to the "name" parameter. This allows an authenticated attacker…

  • CVE-2026-30529HigMar 27, 2026
    risk 0.57cvss 8.8epss 0.00

    A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_user action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an authenticated attacker…

  • CVE-2026-30534HigMar 27, 2026
    risk 0.54cvss 8.3epss 0.00

    A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via the "id" parameter.

  • CVE-2023-24647HigFeb 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Food Ordering System v2.0 was discovered to contain a SQL injection vulnerability via the email parameter.

  • CVE-2024-0247HigJan 5, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in CodeAstro Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /admin/ of the component Admin Panel. The manipulation of the argument Username leads to sql injection. The attack can be initiated…

  • CVE-2023-0332HigJan 17, 2023
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified as critical. Affected is an unknown function of the file admin/manage_user.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack…

  • CVE-2025-2387HigMar 17, 2025
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified as critical. Affected is an unknown function of the file /admin/ajax.php?action=add_to_cart. The manipulation of the argument pid leads to sql injection. It is possible to launch…

  • CVE-2023-1432HigMar 16, 2023
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Online Food Ordering System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /fos/admin/ajax.php?action=save_settings of the component POST Request Handler. The manipulation leads to…

  • CVE-2022-32335HigJun 14, 2022
    risk 0.47cvss 7.2epss 0.01

    Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/manage_menu.php?id=.

Page 1 of 3