Oretnom23 Food Ordering Management System vulnerabilities
17 known vulnerabilities affecting oretnom23/food_ordering_management_system.
Total CVEs
17
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM15
Vulnerabilities
Page 1 of 1
CVE-2025-10400MEDIUMCVSS 5.3v1.02025-09-14
CVE-2025-10400 [MEDIUM] CWE-74 CVE-2025-10400: A security vulnerability has been detected in SourceCodester Food Ordering Management System 1.0. Im
A security vulnerability has been detected in SourceCodester Food Ordering Management System 1.0. Impacted is an unknown function of the file /routers/ticket-message.php. Such manipulation of the argument ticket_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
nvd
CVE-2025-9832MEDIUMCVSS 6.9v1.02025-09-02
CVE-2025-9832 [MEDIUM] CWE-74 CVE-2025-9832: A security vulnerability has been detected in SourceCodester Food Ordering Management System 1.0. Af
A security vulnerability has been detected in SourceCodester Food Ordering Management System 1.0. Affected is an unknown function of the file /routers/register-router.php. Such manipulation of the argument phone leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
nvd
CVE-2025-2852MEDIUMCVSS 5.1≤ 1.02025-03-27
CVE-2025-2852 [MEDIUM] CWE-74 CVE-2025-2852: A vulnerability has been found in SourceCodester Food Ordering Management System up to 1.0 and class
A vulnerability has been found in SourceCodester Food Ordering Management System up to 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/menus/view_menu.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the p
nvd
CVE-2024-8711MEDIUMCVSS 6.9v1.02024-09-12
CVE-2024-8711 [MEDIUM] CWE-548 CVE-2024-8711: A vulnerability, which was classified as problematic, has been found in SourceCodester Food Ordering
A vulnerability, which was classified as problematic, has been found in SourceCodester Food Ordering Management System 1.0. Affected by this issue is some unknown functionality of the file /includes/. The manipulation leads to exposure of information through directory listing. The attack may be launched remotely. The exploit has been disclosed to the
nvd
CVE-2024-8582MEDIUMCVSS 5.3v1.02024-09-08
CVE-2024-8582 [MEDIUM] CWE-79 CVE-2024-8582: A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as pr
A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument description leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may
nvd
CVE-2024-8558MEDIUMCVSS 5.3v1.02024-09-07
CVE-2024-8558 [MEDIUM] CWE-1284 CVE-2024-8558: A vulnerability classified as problematic was found in SourceCodester Food Ordering Management Syste
A vulnerability classified as problematic was found in SourceCodester Food Ordering Management System 1.0. This vulnerability affects unknown code of the file /foms/routers/place-order.php of the component Price Handler. The manipulation of the argument total leads to improper validation of specified quantity in input. The attack can be initiated rem
nvd
CVE-2024-8557MEDIUMCVSS 5.3v1.02024-09-07
CVE-2024-8557 [MEDIUM] CWE-89 CVE-2024-8557: A vulnerability classified as critical has been found in SourceCodester Food Ordering Management Sys
A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System 1.0. This affects an unknown part of the file /foms/routers/cancel-order.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2024-8416MEDIUMCVSS 5.3v1.02024-09-04
CVE-2024-8416 [MEDIUM] CWE-89 CVE-2024-8416: A vulnerability was found in SourceCodester Food Ordering Management System 1.0. It has been classif
A vulnerability was found in SourceCodester Food Ordering Management System 1.0. It has been classified as critical. This affects an unknown part of the file /routers/ticket-status.php. The manipulation of the argument ticket_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may
nvd
CVE-2024-8415MEDIUMCVSS 5.3v1.02024-09-04
CVE-2024-8415 [MEDIUM] CWE-89 CVE-2024-8415: A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as cr
A vulnerability was found in SourceCodester Food Ordering Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /routers/add-ticket.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be use
nvd
CVE-2024-6213MEDIUMCVSS 6.9v1.02024-06-21
CVE-2024-6213 [MEDIUM] CWE-89 CVE-2024-6213: A vulnerability was found in SourceCodester Food Ordering Management System up to 1.0. It has been c
A vulnerability was found in SourceCodester Food Ordering Management System up to 1.0. It has been classified as critical. This affects an unknown part of the file login.php of the component Login Panel. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to th
nvd
CVE-2024-6214MEDIUMCVSS 5.3v1.02024-06-21
CVE-2024-6214 [MEDIUM] CWE-89 CVE-2024-6214: A vulnerability was found in SourceCodester Food Ordering Management System 1.0. It has been declare
A vulnerability was found in SourceCodester Food Ordering Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file add-item.php. The manipulation of the argument price leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-269278
nvd
CVE-2024-6216MEDIUMCVSS 5.3v1.02024-06-21
CVE-2024-6216 [MEDIUM] CWE-89 CVE-2024-6216: A vulnerability classified as critical has been found in SourceCodester Food Ordering Management Sys
A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System 1.0. Affected is an unknown function of the file add-users.php. The manipulation of the argument contact leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifie
nvd
CVE-2024-6217MEDIUMCVSS 5.3v1.02024-06-21
CVE-2024-6217 [MEDIUM] CWE-89 CVE-2024-6217: A vulnerability classified as critical was found in SourceCodester Food Ordering Management System 1
A vulnerability classified as critical was found in SourceCodester Food Ordering Management System 1.0. Affected by this vulnerability is an unknown functionality of the file user-router.php. The manipulation of the argument 1_verified leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be u
nvd
CVE-2024-6215MEDIUMCVSS 5.3v1.02024-06-21
CVE-2024-6215 [MEDIUM] CWE-89 CVE-2024-6215: A vulnerability was found in SourceCodester Food Ordering Management System up to 1.0. It has been r
A vulnerability was found in SourceCodester Food Ordering Management System up to 1.0. It has been rated as critical. This issue affects some unknown processing of the file view-ticket-admin.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used
nvd
CVE-2023-2594CRITICALCVSS 9.8v1.02023-05-09
CVE-2023-2594 [CRITICAL] CWE-89 CVE-2023-2594: A vulnerability, which was classified as critical, was found in SourceCodester Food Ordering Managem
A vulnerability, which was classified as critical, was found in SourceCodester Food Ordering Management System 1.0. Affected is an unknown function of the component Registration. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is VDB-228396.
nvd
CVE-2022-42990HIGHCVSS 7.2v1.02022-11-07
CVE-2022-42990 [HIGH] CWE-89 CVE-2022-42990: Food Ordering Management System v1.0 was discovered to contain a SQL injection vulnerability via the
Food Ordering Management System v1.0 was discovered to contain a SQL injection vulnerability via the component /foms/all-orders.php?status=Cancelled%20by%20Customer.
nvd
CVE-2022-43046MEDIUMCVSS 4.8v1.02022-11-07
CVE-2022-43046 [MEDIUM] CWE-79 CVE-2022-43046: Food Ordering Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerab
Food Ordering Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /foms/place-order.php.
nvd