The Fast Food Ordering System Project maintains a focused ordering and point-of-sale application that, despite modest overall prevalence, supports transaction processing and customer data handling across multiple deployments. Vulnerabilities in this vendor skew toward serious outcomes and recur consistently through web-application input-handling weaknesses: SQL injection, cross-site scripting, and path traversal defects that reflect the exposure of user-facing order entry and backend data access. Defenders should prioritize patches for this vendor's releases, especially where instances are internet-reachable or handle payment data; current severity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fast Food Ordering System Project over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-32336CRITICAL Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/view_menu.php?id=. | Jun 14, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-32328CRITICAL Fast Food Ordering System v1.0 is vulnerable to Delete any file. via /ffos/classes/Master.php?f=delete_img. | Jun 14, 2022 | 9.1 | 27 | NO | NO |
CVE-2022-32335HIGH Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/manage_menu.php?id=. | Jun 14, 2022 | 7.2 | 23 | NO | NO |
CVE-2022-32334HIGH Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/categories/manage_category.php?id=. | Jun 14, 2022 | 7.2 | 23 | NO | NO |
CVE-2022-32333HIGH Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/sales/receipt.php?id=. | Jun 14, 2022 | 7.2 | 23 | NO | NO |
CVE-2022-32332HIGH Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/classes/Master.php?f=delete_category. | Jun 14, 2022 | 7.2 | 23 | NO | NO |
CVE-2022-32331HIGH Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/categories/view_category.php?id=. | Jun 14, 2022 | 7.2 | 23 | NO | NO |
CVE-2022-3015MEDIUM A vulnerability, which was classified as problematic, has been found in oretnom23 Fast Food Ordering System. This issue affects some unknown processing of the file admin/?page=repo | Aug 27, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-3012HIGH A vulnerability was found in oretnom23 Fast Food Ordering System. It has been rated as critical. Affected by this issue is some unknown functionality of the file ffos/admin/reports | Aug 27, 2022 | 8.8 | 22 | NO | NO |
CVE-2022-43082MEDIUM A cross-site scripting (XSS) vulnerability in /fastfood/purchase.php of Fast Food Ordering System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted paylo | Nov 1, 2022 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fast Food Ordering System Project.
Media articles that mention a CVE ID that affects a product developed by Fast Food Ordering System Project — matched by CVE ID, not by vendor name.