Known Vulnerabilities for products from Online Ordering System Project
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Online Ordering System Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-7755 json | A vulnerability was found in code-projects Online Ordering System 1.0. It has been rated as critical. This issue affects some... | Not Provided | 2025-07-17 | 2026-04-29 |
| CVE-2022-36581 json | Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /admin/... | 7.5 - HIGH | 2022-08-31 | 2022-09-02 |
| CVE-2022-36580 json | An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering System v... | 7.2 - HIGH | 2022-08-31 | 2022-09-02 |
| CVE-2022-31357 json | Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php... | 9.8 - CRITICAL | 2022-06-17 | 2022-06-27 |
| CVE-2022-31356 json | Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/store/index.php?vie... | 9.8 - CRITICAL | 2022-06-17 | 2022-06-27 |
| CVE-2022-31355 json | Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&sear... | 9.8 - CRITICAL | 2022-06-17 | 2022-06-27 |
| CVE-2022-31338 json | Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/user/index.php?view=edit&id=. | 9.8 - CRITICAL | 2022-06-02 | 2022-06-10 |
| CVE-2022-31337 json | Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/category/index.php?view=edit&id=. | 9.8 - CRITICAL | 2022-06-02 | 2022-06-10 |
| CVE-2022-31336 json | Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/loaddata.php. | 9.8 - CRITICAL | 2022-06-02 | 2022-06-10 |
| CVE-2022-31335 json | Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/index.php?view=edit&id=. | 9.8 - CRITICAL | 2022-06-02 | 2022-06-10 |
| CVE-2022-31329 json | Online Ordering System By janobe 2.3.2 is vulnerable to SQL Injection via /ordering/admin/orders/loaddata.php. | 9.8 - CRITICAL | 2022-06-02 | 2022-06-10 |
| CVE-2022-31328 json | Online Ordering System By janobe 2.3.2 has SQL Injection via /ordering/admin/products/index.php?view=edit&id=. | 9.8 - CRITICAL | 2022-06-02 | 2022-06-10 |
| CVE-2022-31327 json | Online Ordering System By janobe 2.3.2 is vulneranle to SQL Injection via /ordering/index.php?q=products&id=. | 9.8 - CRITICAL | 2022-06-02 | 2022-06-10 |
| CVE-2022-30799 json | Online Ordering System v1.0 by oretnom23 has SQL injection via store/orderpage.php. | 7.2 - HIGH | 2022-06-02 | 2022-06-10 |
| CVE-2022-30798 json | Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/viewreport.php. | 7.2 - HIGH | 2022-06-02 | 2022-06-10 |
| CVE-2022-30797 json | Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php. | 9.8 - CRITICAL | 2022-06-02 | 2022-06-10 |
| CVE-2022-30795 json | Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductimage.php. | 7.2 - HIGH | 2022-06-02 | 2022-06-10 |
| CVE-2022-30794 json | Online Ordering System v1.0 by oretnom23 is vulnerable to SQL Injection via admin/editproductetails.php. | 7.2 - HIGH | 2022-06-02 | 2022-06-10 |
| CVE-2021-28295 json | Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, whic... | 7.5 - HIGH | 2021-03-16 | 2021-03-22 |
| CVE-2021-28294 json | Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which... | 9.8 - CRITICAL | 2021-03-16 | 2021-03-22 |