Projectworlds
Projectworlds Online Food Ordering System: vulnerabilidades y CVE
Projectworlds Online Food Ordering System tiene 13 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 10 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses2
Críticas10
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-2136 | Media (5.5) | 0.38% | — | 8 feb 2026 | A flaw has been found in projectworlds Online Food Ordering System 1.0. This affects an unknown function of the file /view-ticket.php. Executing a manipulation of the argument ID can lead to sql injection. It is… |
| CVE-2025-11604 | Media (5.5) | 0.42% | — | 11 oct 2025 | A vulnerability was determined in projectworlds Online Ordering Food System 1.0. This issue affects some unknown processing of the file /all-orders.php. This manipulation of the argument Status causes sql injection.… |
| CVE-2025-4936 | Media (6.9) | 0.51% | — | 19 may 2025 | A vulnerability was found in projectworlds Online Food Ordering System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin-page.php. The manipulation of the argument 1_price leads… |
| CVE-2024-57328 | Crítica (9.8) | 0.56% | — | 23 ene 2025 | A SQL Injection vulnerability exists in the login form of Online Food Ordering System v1.0. The vulnerability arises because the input fields username and password are not properly sanitized, allowing attackers to… |
| CVE-2023-45344 | Crítica (9.8) | 0.70% | — | 2 nov 2023 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_balance' parameter of the routers/user-router.php resource does not validate the characters received and… |
| CVE-2023-45343 | Crítica (9.8) | 0.70% | — | 2 nov 2023 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'ticket_id' parameter of the routers/ticket-message.php resource does not validate the characters received… |
| CVE-2023-45342 | Crítica (9.8) | 0.70% | — | 2 nov 2023 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'phone' parameter of the routers/register-router.php resource does not validate the characters received and… |
| CVE-2023-45341 | Crítica (9.8) | 0.70% | — | 2 nov 2023 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The '*_price' parameter of the routers/menu-router.php resource does not validate the characters received and… |
| CVE-2023-45340 | Crítica (9.8) | 0.70% | — | 2 nov 2023 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'phone' parameter of the routers/details-router.php resource does not validate the characters received and… |
| CVE-2023-45336 | Crítica (9.8) | 0.70% | — | 2 nov 2023 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'password' parameter of the routers/router.php resource does not validate the characters received and they… |
| CVE-2023-45334 | Crítica (9.8) | 0.70% | — | 2 nov 2023 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'status' parameter of the routers/edit-orders.php resource does not validate the characters received and they… |
| CVE-2023-45325 | Crítica (9.8) | 0.70% | — | 2 nov 2023 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'address' parameter of the routers/add-users.php resource does not validate the characters received and they… |
| CVE-2023-45323 | Crítica (9.8) | 0.70% | — | 2 nov 2023 | Online Food Ordering System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'name' parameter of the routers/add-item.php resource does not validate the characters received and they are… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Projectworlds
Online Examination System · 17Advanced Library Management System · 17Online Time Table Generator · 15Life Insurance Management System · 14Travel Management System · 14Online Lawyer Management System · 10Online Book Store Project IN PHP · 10Visitor Management System · 9Online Admission System · 7Online Matrimonial Project · 7Hospital Management System IN PHP · 7Online ART Gallery Shop · 6