📦 Simple Food Ordering System

by Fabian

🔍 What is Simple Food Ordering System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-12301

HIGH CVSS 7.3 Oct 27, 2025

This vulnerability allows remote attackers to upload arbitrary files to the Simple Food Ordering System 1.0 via the photo parameter in /editproduct.php. This affects all installations of the software ...

CVE-2025-11396

HIGH CVSS 7.3 Oct 7, 2025

This SQL injection vulnerability in Simple Food Ordering System 1.0 allows remote attackers to execute arbitrary SQL commands via the Category parameter in product.php. This could lead to data theft, ...

CVE-2025-13290

MEDIUM CVSS 6.3 Nov 17, 2025

This SQL injection vulnerability in Simple Food Ordering System 1.0 allows attackers to manipulate database queries through the /saveorder.php endpoint. Attackers can potentially read, modify, or dele...

CVE-2025-12300

MEDIUM CVSS 4.3 Oct 27, 2025

This vulnerability allows attackers to inject malicious scripts into the Simple Food Ordering System 1.0 through the cname parameter in /addcategory.php. The cross-site scripting (XSS) attack can be e...

CVE-2025-12298

MEDIUM CVSS 4.3 Oct 27, 2025

A cross-site scripting (XSS) vulnerability exists in code-projects Simple Food Ordering System 1.0, specifically in the /editcategory.php file's pname parameter. Attackers can inject malicious scripts...

CVE-2025-12299

MEDIUM CVSS 4.3 Oct 27, 2025

This vulnerability allows attackers to inject malicious scripts into the Simple Food Ordering System 1.0 through the /addproduct.php endpoint. When users view affected pages, these scripts execute in ...

CVE-2025-11613

MEDIUM CVSS 6.3 Oct 11, 2025

This SQL injection vulnerability in Simple Food Ordering System 1.0 allows attackers to execute arbitrary SQL commands via the 'cname' parameter in /addcategory.php. Attackers can potentially access, ...

CVE-2025-11612

MEDIUM CVSS 6.3 Oct 11, 2025

This SQL injection vulnerability in Simple Food Ordering System 1.0 allows attackers to manipulate database queries through the Category parameter in /addproduct.php. Attackers can potentially read, m...