Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Simple Food Website Project Subscribe
Filtered by product Simple Food Website
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-30015 1 Simple Food Website Project 1 Simple Food Website 2022-05-29 3.5 LOW 5.4 MEDIUM
In Simple Food Website 1.0, a moderation can put the Cross Site Scripting Payload in any of the fields on http://127.0.0.1:1234/food/admin/all_users.php like Full Username, etc .This causes stored xss.
CVE-2022-30014 1 Simple Food Website Project 1 Simple Food Website 2022-05-29 6.8 MEDIUM 8.8 HIGH
Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover admin/moderater account.
CVE-2021-34166 1 Simple Food Website Project 1 Simple Food Website 2022-05-03 7.5 HIGH 9.8 CRITICAL
A SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authentication and become Admin.