CVE-2026-4533 describes a high-severity SQL injection vulnerability in code-projects Simple Food Ordering System 1.0, specifically affecting the 'Status' argument within the all-tickets.php file. Rated 8.8 CVSS, this flaw allows a remote attacker with low privileges to achieve full compromise of data confidentiality, integrity, and system availability. The attack complexity is low, making it straightforward to exploit. Public exploit code is available, increasing the immediate risk of exploitation. Although not yet observed in widespread active attacks (KEV: No), its inclusion on the "Hot List" signifies its critical nature and potential for future targeting.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:carmelo:simple_food_order_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.