📦 Online Food Ordering System

by Projectworlds

🔍 What is Online Food Ordering System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-57328

CRITICAL CVSS 9.8 Jan 23, 2025

This SQL injection vulnerability in Online Food Ordering System v1.0 allows attackers to bypass authentication by injecting malicious SQL queries through the login form. Attackers can gain unauthorize...

CVE-2023-45344

CRITICAL CVSS 9.8 Nov 2, 2023

Online Food Ordering System v1.0 has unauthenticated SQL injection vulnerabilities in the '*_balance' parameter of routers/user-router.php. Attackers can execute arbitrary SQL commands without authent...

CVE-2023-45334

CRITICAL CVSS 9.8 Nov 2, 2023

Online Food Ordering System v1.0 has unauthenticated SQL injection vulnerabilities in the 'status' parameter of routers/edit-orders.php. Attackers can execute arbitrary SQL commands without authentica...

CVE-2023-45336

CRITICAL CVSS 9.8 Nov 2, 2023

Online Food Ordering System v1.0 has unauthenticated SQL injection vulnerabilities in the routers/router.php resource, allowing attackers to execute arbitrary SQL commands without authentication. This...

CVE-2023-45340

CRITICAL CVSS 9.8 Nov 2, 2023

Online Food Ordering System v1.0 has unauthenticated SQL injection vulnerabilities in the 'phone' parameter of routers/details-router.php, allowing attackers to execute arbitrary SQL commands without ...

CVE-2023-45342

CRITICAL CVSS 9.8 Nov 2, 2023

Online Food Ordering System v1.0 has unauthenticated SQL injection vulnerabilities in the phone parameter of the registration router. Attackers can execute arbitrary SQL commands without authenticatio...

CVE-2023-45325

CRITICAL CVSS 9.8 Nov 2, 2023

Online Food Ordering System v1.0 contains unauthenticated SQL injection vulnerabilities in the routers/add-users.php endpoint. Attackers can exploit the 'address' parameter to execute arbitrary SQL co...

CVE-2026-2136

HIGH CVSS 7.3 Feb 8, 2026

CVE-2026-2136 is a SQL injection vulnerability in projectworlds Online Food Ordering System 1.0 that allows remote attackers to execute arbitrary SQL commands via the ID parameter in /view-ticket.php....

CVE-2025-11604

HIGH CVSS 7.3 Oct 11, 2025

CVE-2025-11604 is a SQL injection vulnerability in projectworlds Online Ordering Food System 1.0 that allows attackers to manipulate database queries through the Status parameter in /all-orders.php. T...

CVE-2025-4936

HIGH CVSS 7.3 May 19, 2025

CVE-2025-4936 is a critical SQL injection vulnerability in projectworlds Online Food Ordering System 1.0 that allows remote attackers to execute arbitrary SQL commands via the 1_price parameter in /ad...