CVE-2026-4469 is a critical SQL injection vulnerability found in itsourcecode Online Frozen Foods Ordering System 1.0, specifically within the /admin/admin_edit_menu_action.php file when processing the product_name argument. This flaw carries a CVSSv3.1 score of 9.8 (Critical) due to its remote exploitability with low attack complexity, requiring no authentication or user interaction. Successful exploitation can lead to a complete compromise of confidentiality, integrity, and availability of the system. While the original description indicates a public exploit is available, it is not present in major exploit frameworks like Metasploit or ExploitDB. There is currently no evidence of active exploitation (not in KEV or Hot List), and community discussion and media coverage are absent, correlating with a very low EPSS score.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:adonesevangelista:online_frozen_foods_ordering_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.