The Online Ordering System Project maintains a narrowly scoped but notably prominent web application platform used across retail and hospitality contexts. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes, with a substantial share reaching the highest severity ratings and reflecting fundamental input-handling and access-control shortcomings in the platform. The exposure concentrates in the core ordering system product and recurs through weakness classes including SQL injection, unrestricted file uploads, and improper access control—classic web-application flaws that create direct pathways to data compromise and unauthorized system manipulation. Defenders should treat vulnerabilities in this vendor as high-priority across deployments, particularly where the platform processes payment data or customer information. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Online Ordering System Project over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-31357CRITICAL Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/admin/inventory/index.php?view=edit&id=. | Jun 17, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-31338CRITICAL Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/user/index.php?view=edit&id=. | Jun 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-31328CRITICAL Online Ordering System By janobe 2.3.2 has SQL Injection via /ordering/admin/products/index.php?view=edit&id=. | Jun 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-30797CRITICAL Online Ordering System 1.0 by oretnom23 is vulnerable to SQL Injection via admin/vieworders.php. | Jun 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-28294CRITICAL Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, which may lead to remote code execution (RCE). | Mar 16, 2021 | 9.8 | 31 | NO | NO |
CVE-2022-31337CRITICAL Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/category/index.php?view=edit&id=. | Jun 2, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-25211CRITICAL Arbitrary file upload vulnerability in SourceCodester Ordering System v 1.0 allows attackers to execute arbitrary code, via the file upload to ordering\admin\products\edit.php. | Jul 22, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-28295HIGH Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php, which may lead to database information disclosure. | Mar 16, 2021 | 7.5 | 30 | NO | NO |
CVE-2022-31355CRITICAL Online Ordering System v2.3.2 was discovered to contain a SQL injection vulnerability via /ordering/index.php?q=category&search=. | Jun 17, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-31336CRITICAL Online Ordering System 2.3.2 is vulnerable to SQL Injection via /ordering/admin/stockin/loaddata.php. | Jun 2, 2022 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Online Ordering System Project.
Media articles that mention a CVE ID that affects a product developed by Online Ordering System Project — matched by CVE ID, not by vendor name.