HOMEVULNERABILITIESVENDORSOnline Ordering System Project

Online Ordering System ProjectCVEs & Vulnerabilities

21 CVEs affecting Online Ordering System Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

online ordering system 21
CVE-2025-7755HIGH

A vulnerability was found in code-projects Online Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/edit_product.php. The manipulation of the argument image leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

18 Jul 2025
8.8
CVSS
CVE-2022-36581HIGH

Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /admin/login.php.

31 Aug 2022
7.5
CVSS
CVE-2022-36580HIGH

An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering System v2.3.2 allows attackers to execute arbitrary code via a crafted PHP file.

31 Aug 2022
7.2
CVSS
CVE-2022-31357CRITICAL

Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=.

17 Jun 2022
9.8
CVSS
CVE-2022-31356CRITICAL

Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?view=edit&id=.

17 Jun 2022
9.8
CVSS
CVE-2022-31355CRITICAL

Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=.

17 Jun 2022
9.8
CVSS
CVE-2022-31338CRITICAL

Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/user/index.php?view=edit&id=.

2 Jun 2022
9.8
CVSS
CVE-2022-31337CRITICAL

Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/category/index.php?view=edit&id=.

2 Jun 2022
9.8
CVSS
CVE-2022-31336CRITICAL

Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/loaddata.php.

2 Jun 2022
9.8
CVSS
CVE-2022-31335CRITICAL

Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/index.php?view=edit&id=.

2 Jun 2022
9.8
CVSS
CVE-2022-31329CRITICAL

Online Ordering System By janobe 2.3.2 is vulnerable to SQL Injection via /ordering/admin/orders/loaddata.php.

2 Jun 2022
9.8
CVSS
CVE-2022-31328CRITICAL

Online Ordering System By janobe 2.3.2 has SQL Injection via /ordering/admin/products/index.php?view=edit&id=.

2 Jun 2022
9.8
CVSS
CVE-2022-31327CRITICAL

Online Ordering System By janobe 2.3.2 is vulneranle to SQL Injection via /ordering/index.php?q=products&id=.

2 Jun 2022
9.8
CVSS
CVE-2022-30799HIGH

Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php.

2 Jun 2022
7.2
CVSS
CVE-2022-30798HIGH

Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php.

2 Jun 2022
7.2
CVSS
CVE-2022-30797CRITICAL

Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php.

2 Jun 2022
9.8
CVSS
CVE-2022-30795HIGH

Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php.

2 Jun 2022
7.2
CVSS
CVE-2022-30794HIGH

Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php.

2 Jun 2022
7.2
CVSS
CVE-2021-25211CRITICAL

Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, via the file upload to ordering\admin\products\edit.php.

22 Jul 2021
9.8
CVSS
CVE-2021-28295HIGH

Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure.

16 Mar 2021
7.5
CVSS
CVE-2021-28294CRITICAL

Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE).

16 Mar 2021
9.8
CVSS
← PrevPage 1 / 1Next →
Online Ordering System Project CVEs & Vulnerabilities — 21 Tracked