Online Food Ordering System
75 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Online Food Ordering System, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Online Food Ordering System CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 2 |
| 2025-01 | 1 |
| 2025-02 | 0 |
| 2025-03 | 1 |
| 2025-04 | 0 |
| 2025-05 | 9 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 1 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 1 |
| 2026-03 | 13 |
| 2026-04 | 1 |
| 2026-05 | 0 |
| 2026-06 | 1 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 3 |
Severity
How the 75 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical23
- High28
- Medium20
- Low4
Latest CVEs
The 15 most recently published vulnerabilities affecting Online Food Ordering System.
- CVE-2026-92385SourceCodester Online Food Ordering System Category Update update_category.php cross site scripting2.4
- CVE-2026-90855SourceCodester/katojkalemba Online Food Ordering System order.php sql injection7.3
- CVE-2026-90854SourceCodester/katojkalemba Online Food Ordering System category-foods.php sql injection7.3
- CVE-2026-10694SourceCodester Online Food Ordering System index.php include file inclusion7.3
- CVE-2026-5811SourceCodester Online Food Ordering System POST Parameter Actions.php save_product logic error5.4
- CVE-2026-5157code-projects Online Food Ordering System Order order.php cross site scripting4.3
- CVE-2026-30530A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer action). The application fails to properly sanitize u...9.8
- CVE-2026-30531A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_category action). The application fails to properly sanitize u...8.8
- CVE-2026-30529A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_user action). The application fails to properly sanitize user ...8.8
- CVE-2026-30533A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter.9.8
- CVE-2026-30527A Stored Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Category management module within the admin panel. The application fails to proper...5.4
- CVE-2026-30532A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter.9.8
- CVE-2026-30534A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via the "id" parameter.8.3
- CVE-2026-4900code-projects Online Food Ordering System localhost.sql privilege escalation5.3
- CVE-2026-4899code-projects Online Food Ordering System food.php cross site scripting2.4
Product grouping is registry-driven, with AI assist and human review. How it works