Sourcecodester Online Food Ordering System
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Sourcecodester Online Food Ordering System.
By the Year
In 2026 there have been 4 vulnerabilities in Sourcecodester Online Food Ordering System with an average score of 6.5 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 4 | 6.48 |
It may take a day or so for new Online Food Ordering System vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Sourcecodester Online Food Ordering System Security Vulnerabilities
A vulnerability has been found in SourceCodester Online Food Ordering System 1.0
CVE-2026-92385
4.8 - Medium
- September 16, 2026
A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/update_category.php of the component Category Update. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
XSS
SQLi in SourceCodester katojkalemba OOS 1.0 via /web/order.php ID param
CVE-2026-90855
6.9 - Medium
- September 15, 2026
A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0. This affects an unknown function of the file /web/order.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
SQL Injection
SQLi in SourceCodester/katojkalemba Food Ordering System 1.0 /web/category-foods.php
CVE-2026-90854
6.9 - Medium
- September 15, 2026
A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted element is an unknown function of the file /web/category-foods.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.
SQL Injection
SourceCodester OOS 2.0 index.php include via page param (CVE-2026-10694)
CVE-2026-10694
7.3 - High
- June 03, 2026
A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function include of the file /index.php. The manipulation of the argument page results in file inclusion. The attack can be launched remotely. The exploit is now public and may be used.
External Control of File Name or Path
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Sourcecodester Online Food Ordering System or by Sourcecodester? Click the Watch button to subscribe.