Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Online Ordering System Project

First CVE: Mar 16, 2021Active for: 5 yearsTotal CVEs: 21
46.4
VTI Score
High

The Online Ordering System Project maintains a narrowly scoped but notably prominent web application platform used across retail and hospitality contexts. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes, with a substantial share reaching the highest severity ratings and reflecting fundamental input-handling and access-control shortcomings in the platform. The exposure concentrates in the core ordering system product and recurs through weakness classes including SQL injection, unrestricted file uploads, and improper access control—classic web-application flaws that create direct pathways to data compromise and unauthorized system manipulation. Defenders should treat vulnerabilities in this vendor as high-priority across deployments, particularly where the platform processes payment data or customer information. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
7.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
8.9
Avg CVSS Score
Higher Avg CVSS Score than 87% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Online Ordering System Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 16, 2021
5 years ago
Most Recent CVE
Jul 17, 2025
372 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-31357CRITICAL
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=.
Jun 17, 20229.831NONO
CVE-2022-31338CRITICAL
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/user/index.php?view=edit&id=.
Jun 2, 20229.831NONO
CVE-2022-31328CRITICAL
Online Ordering System By janobe 2.3.2 has SQL Injection via /ordering/admin/products/index.php?view=edit&id=.
Jun 2, 20229.831NONO
CVE-2022-30797CRITICAL
Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php.
Jun 2, 20229.831NONO
CVE-2021-28294CRITICAL
Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE).
Mar 16, 20219.831NONO
CVE-2022-31337CRITICAL
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/category/index.php?view=edit&id=.
Jun 2, 20229.830NONO
CVE-2021-25211CRITICAL
Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, via the file upload to ordering\admin\products\edit.php.
Jul 22, 20219.830NONO
CVE-2021-28295HIGH
Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure.
Mar 16, 20217.530NONO
CVE-2022-31355CRITICAL
Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=.
Jun 17, 20229.829NONO
CVE-2022-31336CRITICAL
Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/loaddata.php.
Jun 2, 20229.829NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
38%
62%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network21 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None21 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (4.8%)
High5 (23.8%)
None15 (71.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Online Ordering System Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Online Ordering System Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Online Ordering System Project's Products

View all 2 CNAs →

Top CWEs