Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Online Ordering System Project Subscribe
Total 20 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-36581 1 Online Ordering System Project 1 Online Ordering System 2022-09-02 N/A 7.5 HIGH
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /admin/login.php.
CVE-2022-36580 1 Online Ordering System Project 1 Online Ordering System 2022-09-02 N/A 7.2 HIGH
An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering System v2.3.2 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-31355 1 Online Ordering System Project 1 Online Ordering System 2022-06-27 7.5 HIGH 9.8 CRITICAL
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=.
CVE-2022-31356 1 Online Ordering System Project 1 Online Ordering System 2022-06-27 7.5 HIGH 9.8 CRITICAL
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=.
CVE-2022-31357 1 Online Ordering System Project 1 Online Ordering System 2022-06-27 7.5 HIGH 9.8 CRITICAL
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=.
CVE-2022-30799 1 Online Ordering System Project 1 Online Ordering System 2022-06-10 6.5 MEDIUM 7.2 HIGH
Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php.
CVE-2022-30798 1 Online Ordering System Project 1 Online Ordering System 2022-06-10 6.5 MEDIUM 7.2 HIGH
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php.
CVE-2022-30797 1 Online Ordering System Project 1 Online Ordering System 2022-06-10 7.5 HIGH 9.8 CRITICAL
Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php.
CVE-2022-30795 1 Online Ordering System Project 1 Online Ordering System 2022-06-10 6.5 MEDIUM 7.2 HIGH
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php.
CVE-2022-30794 1 Online Ordering System Project 1 Online Ordering System 2022-06-10 6.5 MEDIUM 7.2 HIGH
Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php.
CVE-2022-31328 1 Online Ordering System Project 1 Online Ordering System 2022-06-10 7.5 HIGH 9.8 CRITICAL
Online Ordering System By janobe 2.3.2 has SQL Injection via /ordering/admin/products/index.php?view=edit&id=.
CVE-2022-31329 1 Online Ordering System Project 1 Online Ordering System 2022-06-10 7.5 HIGH 9.8 CRITICAL
Online Ordering System By janobe 2.3.2 is vulnerable to SQL Injection via /ordering/admin/orders/loaddata.php.
CVE-2022-31335 1 Online Ordering System Project 1 Online Ordering System 2022-06-10 7.5 HIGH 9.8 CRITICAL
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/index.php?view=edit&id=.
CVE-2022-31336 1 Online Ordering System Project 1 Online Ordering System 2022-06-10 7.5 HIGH 9.8 CRITICAL
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/loaddata.php.
CVE-2022-31338 1 Online Ordering System Project 1 Online Ordering System 2022-06-10 7.5 HIGH 9.8 CRITICAL
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/user/index.php?view=edit&id=.
CVE-2022-31337 1 Online Ordering System Project 1 Online Ordering System 2022-06-10 7.5 HIGH 9.8 CRITICAL
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/category/index.php?view=edit&id=.
CVE-2022-31327 1 Online Ordering System Project 1 Online Ordering System 2022-06-10 7.5 HIGH 9.8 CRITICAL
Online Ordering System By janobe 2.3.2 is vulneranle to SQL Injection via /ordering/index.php?q=products&id=.
CVE-2021-25211 1 Online Ordering System Project 1 Online Ordering System 2021-09-13 7.5 HIGH 9.8 CRITICAL
Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, via the file upload to ordering\admin\products\edit.php.
CVE-2021-28295 1 Online Ordering System Project 1 Online Ordering System 2021-03-22 5.0 MEDIUM 7.5 HIGH
Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure.
CVE-2021-28294 1 Online Ordering System Project 1 Online Ordering System 2021-03-22 7.5 HIGH 9.8 CRITICAL
Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE).