The Online Pizza Ordering System Project maintains a web application focused on e-commerce order management, a domain where internet-facing input handling and session management create persistent exposure to application-layer flaws. Vulnerabilities affecting this system skew strongly toward critical-severity outcomes and recur through weakness classes including SQL injection, cross-site scripting, unrestricted file uploads, cross-site request forgery, and authentication bypass—all characteristic of web applications where inadequate input validation and access control directly compromise user data and transaction integrity. Defenders treating this application as a customer-facing asset should prioritize patching and input-layer hardening; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Online Pizza Ordering System Project over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2246CRITICAL A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file admin/ajax.php?act | Apr 23, 2023 | 9.8 | 35 | NO | YES |
CVE-2023-0906CRITICAL A vulnerability classified as critical was found in SourceCodester Online Pizza Ordering System 1.0. Affected by this vulnerability is the function delete_category of the file ajax | Feb 18, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-30092CRITICAL SourceCodester Online Pizza Ordering System v1.0 is vulnerable to SQL Injection via the QTY parameter. | May 8, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-1460CRITICAL A vulnerability was found in SourceCodester Online Pizza Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file admin/ajax.php?action=sav | Mar 17, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-1392CRITICAL A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. Affected by this vulnerability is the function save_menu. The manipula | Mar 14, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-27210CRITICAL Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/view_order.php. | Mar 9, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-0883CRITICAL A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file /php-opos/index.ph | Feb 17, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-27207CRITICAL Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php. | Mar 9, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-0910CRITICAL A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file view_prod.php of t | Feb 18, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-0988HIGH A vulnerability, which was classified as problematic, has been found in SourceCodester Online Pizza Ordering System 1.0. This issue affects some unknown processing of the file admi | Feb 23, 2023 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Online Pizza Ordering System Project.
Media articles that mention a CVE ID that affects a product developed by Online Pizza Ordering System Project — matched by CVE ID, not by vendor name.