Online ordering system
This hub aggregates every CVE we track for Online ordering system, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
33
CVEs tracked
14
Critical
16
High
0
In CISA KEV
Severity distribution
HIGH16CRITICAL14MEDIUM3
Monthly trend
0
0
0
0
0
1
0
0
0
0
0
0
8
0
0
0
0
3
0
1
0
0
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Online ordering system.
- CVE-2026-24494SQL injection vulnerability in Order Up Online Ordering System9.8
- CVE-2025-14251code-projects Online Ordering System Admin Login admin sql injection7.3
- CVE-2025-14250code-projects Online Ordering System user_contact.php sql injection7.3
- CVE-2025-14249code-projects Online Ordering System user_school.php sql injection7.3
- CVE-2025-8256code-projects Online Ordering System product.php unrestricted upload6.3
- CVE-2025-8248code-projects Online Ordering System signup.php sql injection7.3
- CVE-2025-8236code-projects Online Ordering System edit_product.php sql injection7.3
- CVE-2025-8235code-projects Online Ordering System product.php sql injection7.3
- CVE-2025-8234code-projects Online Ordering System delete_member.php sql injection7.3
- CVE-2025-8233code-projects Online Ordering System user.php sql injection7.3
- CVE-2025-8232code-projects Online Ordering System delete_user.php sql injection7.3
- CVE-2025-7755code-projects Online Ordering System edit_product.php unrestricted upload6.3
- CVE-2024-7488Business Logic Error in RestApp Inc.'s Online Ordering System5.3
- CVE-2022-36581Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via the user_email parameter at /admin/login.php.7.5
- CVE-2022-36580An arbitrary file upload vulnerability in the component /admin/products/controller.php?action=add of Online Ordering System v2.3.2 allows attackers to execute arbitrary code via a crafted PHP file.7.2
Product normalization is registry-driven with AI assist and human review. How it works