Vendor CVEs
Online Ordering System Project
All CVEs
37 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-24494 | Cri | 0.64 | 9.8 | 0.00 | Feb 23, 2026 | SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 allows an unauthenticated attacker to access sensitive backend database data via a crafted store_id parameter in a POST request. | ||
| CVE-2023-48434 | Cri | 0.64 | 9.8 | 0.01 | Dec 20, 2023 | Online Voting System Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the reg_action.php resource does not validate the characters received and they are sent unfiltered to the database. | ||
| CVE-2023-45346 | Cri | 0.64 | 9.8 | 0.01 | Nov 2, 2023 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_role' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database. | ||
| CVE-2023-45344 | Cri | 0.64 | 9.8 | 0.01 | Nov 2, 2023 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_balance' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database. | ||
| CVE-2023-45342 | Cri | 0.64 | 9.8 | 0.01 | Nov 2, 2023 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'phone' parameter of the routers/register-router.php resource does not validate the characters received and they are sent unfiltered to the database. | ||
| CVE-2023-45334 | Cri | 0.64 | 9.8 | 0.01 | Nov 2, 2023 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'status' parameter of the routers/edit-orders.php resource does not validate the characters received and they are sent unfiltered to the database. | ||
| CVE-2023-30122 | Cri | 0.64 | 9.8 | 0.01 | May 5, 2023 | An arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online Food Ordering System v2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file. | ||
| CVE-2023-27210 | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/view_order.php. | ||
| CVE-2023-27207 | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php. | ||
| CVE-2022-31357 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2022 | Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=. | ||
| CVE-2022-31356 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2022 | Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=. | ||
| CVE-2022-31355 | Cri | 0.64 | 9.8 | 0.01 | Jun 17, 2022 | Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=. | ||
| CVE-2022-31338 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/user/index.php?view=edit&id=. | ||
| CVE-2022-31337 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/category/index.php?view=edit&id=. | ||
| CVE-2022-31336 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/loaddata.php. | ||
| CVE-2022-31335 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/index.php?view=edit&id=. | ||
| CVE-2022-31329 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System By janobe 2.3.2 is vulnerable to SQL Injection via /ordering/admin/orders/loaddata.php. | ||
| CVE-2022-31328 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System By janobe 2.3.2 has SQL Injection via /ordering/admin/products/index.php?view=edit&id=. | ||
| CVE-2022-31327 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System By janobe 2.3.2 is vulneranle to SQL Injection via /ordering/index.php?q=products&id=. | ||
| CVE-2022-30797 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php. | ||
| CVE-2021-25211 | Cri | 0.64 | 9.8 | 0.02 | Jul 22, 2021 | Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, via the file upload to ordering\admin\products\edit.php. | ||
| CVE-2021-28294 | Cri | 0.64 | 9.8 | 0.04 | Mar 16, 2021 | Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE). | ||
| CVE-2021-28295 | Hig | 0.50 | 7.5 | 0.16 | Mar 16, 2021 | Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure. | ||
| CVE-2022-36581 | Hig | 0.49 | 7.5 | 0.01 | Aug 31, 2022 | Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /admin/login.php. | ||
| CVE-2022-36580 | Hig | 0.47 | 7.2 | 0.01 | Aug 31, 2022 | An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering System v2.3.2 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-30799 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php. | ||
| CVE-2022-30798 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php. | ||
| CVE-2022-30795 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php. | ||
| CVE-2022-30794 | Hig | 0.47 | 7.2 | 0.01 | Jun 2, 2022 | Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php. | ||
| CVE-2023-27073 | Med | 0.42 | 6.5 | 0.00 | Mar 14, 2023 | A Cross-Site Request Forgery (CSRF) in Online Food Ordering System v1.0 allows attackers to change user details and credentials via a crafted POST request. | ||
| CVE-2025-7755 | Med | 0.41 | 6.3 | 0.00 | Jul 17, 2025 | A vulnerability was found in code-projects Online Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/edit_product.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated… | ||
| CVE-2023-27208 | Med | 0.40 | 6.1 | 0.00 | Mar 9, 2023 | A cross-site scripting (XSS) vulnerability in /php-opos/login.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the redirect parameter. | ||
| CVE-2023-24197 | Med | 0.40 | 6.1 | 0.00 | Feb 6, 2023 | Online Food Ordering System v2 was discovered to contain a SQL injection vulnerability via the id parameter at view_order.php. | ||
| CVE-2023-24195 | Med | 0.40 | 6.1 | 0.00 | Feb 6, 2023 | Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in index.php. | ||
| CVE-2023-24194 | Med | 0.40 | 6.1 | 0.00 | Feb 6, 2023 | Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in navbar.php. | ||
| CVE-2023-24192 | Med | 0.40 | 6.1 | 0.00 | Feb 6, 2023 | Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in login.php. | ||
| CVE-2023-24191 | Med | 0.40 | 6.1 | 0.00 | Feb 6, 2023 | Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in signup.php. |
- risk 0.64cvss 9.8epss 0.00
SQL Injection vulnerability in the /api/integrations/getintegrations endpoint of Order Up Online Ordering System 1.0 allows an unauthenticated attacker to access sensitive backend database data via a crafted store_id parameter in a POST request.
- risk 0.64cvss 9.8epss 0.01
Online Voting System Project v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the reg_action.php resource does not validate the characters received and they are sent unfiltered to the database.
- risk 0.64cvss 9.8epss 0.01
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_role' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database.
- risk 0.64cvss 9.8epss 0.01
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_balance' parameter of the routers/user-router.php resource does not validate the characters received and they are sent unfiltered to the database.
- risk 0.64cvss 9.8epss 0.01
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'phone' parameter of the routers/register-router.php resource does not validate the characters received and they are sent unfiltered to the database.
- risk 0.64cvss 9.8epss 0.01
Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'status' parameter of the routers/edit-orders.php resource does not validate the characters received and they are sent unfiltered to the database.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online Food Ordering System v2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
- risk 0.64cvss 9.8epss 0.01
Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/view_order.php.
- risk 0.64cvss 9.8epss 0.01
Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/user/index.php?view=edit&id=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/category/index.php?view=edit&id=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/loaddata.php.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/index.php?view=edit&id=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System By janobe 2.3.2 is vulnerable to SQL Injection via /ordering/admin/orders/loaddata.php.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System By janobe 2.3.2 has SQL Injection via /ordering/admin/products/index.php?view=edit&id=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System By janobe 2.3.2 is vulneranle to SQL Injection via /ordering/index.php?q=products&id=.
- risk 0.64cvss 9.8epss 0.01
Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php.
- risk 0.64cvss 9.8epss 0.02
Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, via the file upload to ordering\admin\products\edit.php.
- risk 0.64cvss 9.8epss 0.04
Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE).
- risk 0.50cvss 7.5epss 0.16
Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure.
- risk 0.49cvss 7.5epss 0.01
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /admin/login.php.
- risk 0.47cvss 7.2epss 0.01
An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering System v2.3.2 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.47cvss 7.2epss 0.01
Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php.
- risk 0.47cvss 7.2epss 0.01
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php.
- risk 0.47cvss 7.2epss 0.01
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php.
- risk 0.47cvss 7.2epss 0.01
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php.
- risk 0.42cvss 6.5epss 0.00
A Cross-Site Request Forgery (CSRF) in Online Food Ordering System v1.0 allows attackers to change user details and credentials via a crafted POST request.
- risk 0.41cvss 6.3epss 0.00
A vulnerability was found in code-projects Online Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/edit_product.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated…
- risk 0.40cvss 6.1epss 0.00
A cross-site scripting (XSS) vulnerability in /php-opos/login.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the redirect parameter.
- risk 0.40cvss 6.1epss 0.00
Online Food Ordering System v2 was discovered to contain a SQL injection vulnerability via the id parameter at view_order.php.
- risk 0.40cvss 6.1epss 0.00
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in index.php.
- risk 0.40cvss 6.1epss 0.00
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in navbar.php.
- risk 0.40cvss 6.1epss 0.00
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in login.php.
- risk 0.40cvss 6.1epss 0.00
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in signup.php.