Online Ordering System Project Online Ordering System vulnerabilities
21 known vulnerabilities affecting online_ordering_system_project/online_ordering_system.
Total CVEs
21
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL13HIGH7MEDIUM1
Vulnerabilities
Page 1 of 2
CVE-2025-7755MEDIUMCVSS 5.3v1.02025-07-17
CVE-2025-7755 [MEDIUM] CWE-284 CVE-2025-7755: A vulnerability was found in code-projects Online Ordering System 1.0. It has been rated as critical
A vulnerability was found in code-projects Online Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/edit_product.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2022-36580HIGHCVSS 7.2v2.3.22022-08-31
CVE-2022-36580 [HIGH] CWE-434 CVE-2022-36580: An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of
An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering System v2.3.2 allows attackers to execute arbitrary code via a crafted PHP file.
nvd
CVE-2022-36581HIGHCVSS 7.5v2.3.22022-08-31
CVE-2022-36581 [HIGH] CWE-89 CVE-2022-36581: Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_e
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /admin/login.php.
nvd
CVE-2022-31355CRITICALCVSS 9.8v2.3.22022-06-17
CVE-2022-31355 [CRITICAL] CWE-89 CVE-2022-31355: Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=.
nvd
CVE-2022-31356CRITICALCVSS 9.8v2.3.22022-06-17
CVE-2022-31356 [CRITICAL] CWE-89 CVE-2022-31356: Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=.
nvd
CVE-2022-31357CRITICALCVSS 9.8v2.3.22022-06-17
CVE-2022-31357 [CRITICAL] CWE-89 CVE-2022-31357: Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=.
nvd
CVE-2022-31338CRITICALCVSS 9.8v2.3.22022-06-02
CVE-2022-31338 [CRITICAL] CWE-89 CVE-2022-31338: Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/user/index.php?view=
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/user/index.php?view=edit&id=.
nvd
CVE-2022-30797CRITICALCVSS 9.8v1.02022-06-02
CVE-2022-30797 [CRITICAL] CWE-89 CVE-2022-30797: Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php.
Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php.
nvd
CVE-2022-31328CRITICALCVSS 9.8v2.3.22022-06-02
CVE-2022-31328 [CRITICAL] CWE-89 CVE-2022-31328: Online Ordering System By janobe 2.3.2 has SQL Injection via /ordering/admin/products/index.php?view
Online Ordering System By janobe 2.3.2 has SQL Injection via /ordering/admin/products/index.php?view=edit&id=.
nvd
CVE-2022-31327CRITICALCVSS 9.8v2.3.22022-06-02
CVE-2022-31327 [CRITICAL] CWE-89 CVE-2022-31327: Online Ordering System By janobe 2.3.2 is vulneranle to SQL Injection via /ordering/index.php?q=prod
Online Ordering System By janobe 2.3.2 is vulneranle to SQL Injection via /ordering/index.php?q=products&id=.
nvd
CVE-2022-31335CRITICALCVSS 9.8v2.3.22022-06-02
CVE-2022-31335 [CRITICAL] CWE-89 CVE-2022-31335: Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/index.php?vi
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/index.php?view=edit&id=.
nvd
CVE-2022-31336CRITICALCVSS 9.8v2.3.22022-06-02
CVE-2022-31336 [CRITICAL] CWE-89 CVE-2022-31336: Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/loaddata.php
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/loaddata.php.
nvd
CVE-2022-31337CRITICALCVSS 9.8v2.3.22022-06-02
CVE-2022-31337 [CRITICAL] CWE-89 CVE-2022-31337: Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/category/index.php?v
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/category/index.php?view=edit&id=.
nvd
CVE-2022-31329CRITICALCVSS 9.8v2.3.22022-06-02
CVE-2022-31329 [CRITICAL] CWE-89 CVE-2022-31329: Online Ordering System By janobe 2.3.2 is vulnerable to SQL Injection via /ordering/admin/orders/loa
Online Ordering System By janobe 2.3.2 is vulnerable to SQL Injection via /ordering/admin/orders/loaddata.php.
nvd
CVE-2022-30799HIGHCVSS 7.2v1.02022-06-02
CVE-2022-30799 [HIGH] CWE-89 CVE-2022-30799: Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php.
Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php.
nvd
CVE-2022-30795HIGHCVSS 7.2v1.02022-06-02
CVE-2022-30795 [HIGH] CWE-89 CVE-2022-30795: Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.p
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php.
nvd
CVE-2022-30794HIGHCVSS 7.2v1.02022-06-02
CVE-2022-30794 [HIGH] CWE-89 CVE-2022-30794: Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php.
nvd
CVE-2022-30798HIGHCVSS 7.2v1.02022-06-02
CVE-2022-30798 [HIGH] CWE-89 CVE-2022-30798: Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php.
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php.
nvd
CVE-2021-25211CRITICALCVSS 9.8v1.02021-07-22
CVE-2021-25211 [CRITICAL] CWE-434 CVE-2021-25211: Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to exec
Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, via the file upload to ordering\admin\products\edit.php.
nvd
CVE-2021-28294CRITICALCVSS 9.8v1.02021-03-16
CVE-2021-28294 [CRITICAL] CWE-434 CVE-2021-28294: Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store
Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE).
nvd
1 / 2Next →