Oretnom23 Online Food Ordering System vulnerabilities
29 known vulnerabilities affecting oretnom23/online_food_ordering_system.
Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH5MEDIUM10
Vulnerabilities
Page 1 of 2
CVE-2026-30533CRITICALCVSS 9.8v1.02026-03-27
CVE-2026-30533 [CRITICAL] CWE-89 CVE-2026-30533: A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter.
nvd
CVE-2026-30530CRITICALCVSS 9.8v1.02026-03-27
CVE-2026-30530 [CRITICAL] CWE-89 CVE-2026-30530: A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actio
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an attacker to inject malicious SQL commands.
nvd
CVE-2026-30532CRITICALCVSS 9.8v1.02026-03-27
CVE-2026-30532 [CRITICAL] CWE-89 CVE-2026-30532: A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter.
nvd
CVE-2026-30534HIGHCVSS 8.3v1.02026-03-27
CVE-2026-30534 [HIGH] CWE-89 CVE-2026-30534: A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/man
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via the "id" parameter.
nvd
CVE-2026-30531HIGHCVSS 8.8v1.02026-03-27
CVE-2026-30531 [HIGH] CWE-89 CVE-2026-30531: A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actio
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_category action). The application fails to properly sanitize user input supplied to the "name" parameter. This allows an authenticated attacker to inject malicious SQL commands.
nvd
CVE-2026-30529HIGHCVSS 8.8v1.02026-03-27
CVE-2026-30529 [HIGH] CWE-89 CVE-2026-30529: A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actio
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_user action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an authenticated attacker to inject malicious SQL commands.
nvd
CVE-2026-30527MEDIUMCVSS 5.4v1.02026-03-27
CVE-2026-30527 [MEDIUM] CWE-79 CVE-2026-30527: A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Online Food Ordering Syst
A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Category management module within the admin panel. The application fails to properly sanitize user input supplied to the "Category Name" field when creating or updating a category. When an administrator or user visits the Category list p
nvd
CVE-2025-2387MEDIUMCVSS 6.9v2.02025-03-17
CVE-2025-2387 [MEDIUM] CWE-74 CVE-2025-2387: A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified
A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified as critical. Affected is an unknown function of the file /admin/ajax.php?action=add_to_cart. The manipulation of the argument pid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be
nvd
CVE-2024-8604MEDIUMCVSS 6.9v2.02024-09-09
CVE-2024-8604 [MEDIUM] CWE-79 CVE-2024-8604: A vulnerability classified as problematic has been found in SourceCodester Online Food Ordering Syst
A vulnerability classified as problematic has been found in SourceCodester Online Food Ordering System 2.0. This affects an unknown part of the file index.php of the component Create an Account Page. The manipulation of the argument First Name/Last Name leads to cross site scripting. It is possible to initiate the attack remotely.
nvd
CVE-2024-0247CRITICALCVSS 9.8v1.02024-01-05
CVE-2024-0247 [HIGH] CWE-89 CVE-2024-0247: A vulnerability classified as critical was found in CodeAstro Online Food Ordering System 1.0. This
A vulnerability classified as critical was found in CodeAstro Online Food Ordering System 1.0. This vulnerability affects unknown code of the file /admin/ of the component Admin Panel. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-24
nvd
CVE-2023-30122CRITICALCVSS 9.8v2.02023-05-05
CVE-2023-30122 [CRITICAL] CWE-434 CVE-2023-30122: An arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online F
An arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online Food Ordering System v2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
nvd
CVE-2023-1432CRITICALCVSS 9.8v2.02023-03-16
CVE-2023-1432 [HIGH] CWE-284 CVE-2023-1432: A vulnerability was found in SourceCodester Online Food Ordering System 2.0 and classified as critic
A vulnerability was found in SourceCodester Online Food Ordering System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /fos/admin/ajax.php?action=save_settings of the component POST Request Handler. The manipulation leads to improper access controls. The attack may be launched remotely. VDB-223214 is the
nvd
CVE-2023-27073MEDIUMCVSS 6.5v1.02023-03-14
CVE-2023-27073 [MEDIUM] CWE-352 CVE-2023-27073: A Cross-Site Request Forgery (CSRF) in Online Food Ordering System v1.0 allows attackers to change u
A Cross-Site Request Forgery (CSRF) in Online Food Ordering System v1.0 allows attackers to change user details and credentials via a crafted POST request.
nvd
CVE-2023-24646CRITICALCVSS 9.8v2.02023-02-13
CVE-2023-24646 [CRITICAL] CWE-434 CVE-2023-24646: An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System
An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code via a crafted PHP file.
nvd
CVE-2023-24647HIGHCVSS 7.5v2.02023-02-13
CVE-2023-24647 [HIGH] CWE-89 CVE-2023-24647: Food Ordering System v2.0 was discovered to contain a SQL injection vulnerability via the email para
Food Ordering System v2.0 was discovered to contain a SQL injection vulnerability via the email parameter.
nvd
CVE-2023-24191MEDIUMCVSS 6.1v2.02023-02-06
CVE-2023-24191 [MEDIUM] CWE-79 CVE-2023-24191: Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in signup.php.
nvd
CVE-2023-24197MEDIUMCVSS 6.1v2.02023-02-06
CVE-2023-24197 [MEDIUM] CWE-79 CVE-2023-24197: Online Food Ordering System v2 was discovered to contain a SQL injection vulnerability via the id pa
Online Food Ordering System v2 was discovered to contain a SQL injection vulnerability via the id parameter at view_order.php.
nvd
CVE-2023-24195MEDIUMCVSS 6.1v2.02023-02-06
CVE-2023-24195 [MEDIUM] CWE-79 CVE-2023-24195: Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in index.php.
nvd
CVE-2023-24194MEDIUMCVSS 6.1v2.02023-02-06
CVE-2023-24194 [MEDIUM] CWE-79 CVE-2023-24194: Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in navbar.php.
nvd
CVE-2023-24192MEDIUMCVSS 6.1v2.02023-02-06
CVE-2023-24192 [MEDIUM] CWE-79 CVE-2023-24192: Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the redirect parameter in login.php.
nvd
1 / 2Next →