Iresturant Project maintains a web-based restaurant management application with a narrow vulnerability footprint centered on the core Iresturant product and reflecting typical web-application input-handling exposure: cross-site scripting and SQL injection weaknesses. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iresturant Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43439CRITICAL RCE in Add Review Function in iResturant 1.0 Allows remote attacker to execute commands remotely | Dec 20, 2021 | 9.8 | 31 | NO | NO |
CVE-2021-45802CRITICAL MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter values are added to the SQL query without any verification | Jan 25, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-45803HIGH MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is added to the SQL query without additional verification when | Jan 25, 2022 | 8.8 | 27 | NO | NO |
CVE-2021-43438MEDIUM Stored XSS in Signup Form in iResturant 1.0 Allows Remote Attacker to Inject Arbitrary code via NAME and ADDRESS field | Dec 20, 2021 | 5.4 | 20 | NO | NO |
CVE-2021-43436MEDIUM MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt. When an administrator looks at the log of failed logins, the | Jan 12, 2022 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iresturant Project.
Media articles that mention a CVE ID that affects a product developed by Iresturant Project — matched by CVE ID, not by vendor name.