Simple Food Website Project operates a narrowly scoped web application whose vulnerability footprint centers on standard web-layer input-handling and request-validation issues, including cross-site scripting, cross-site request forgery, and SQL injection. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Simple Food Website Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-34166CRITICAL A SQL INJECTION vulnerability in Sourcecodester Simple Food Website 1.0 allows a remote attacker to Bypass Authentication and become Admin. | Jul 30, 2021 | 9.8 | 31 | NO | NO |
CVE-2022-30014HIGH Lumidek Associates Simple Food Website 1.0 is vulnerable to Cross Site Request Forgery (CSRF) which allows anyone to takeover admin/moderater account. | May 23, 2022 | 8.8 | 29 | NO | NO |
CVE-2022-30015MEDIUM In Simple Food Website 1.0, a moderation can put the Cross Site Scripting Payload in any of the fields on http://127.0.0.1:1234/food/admin/all_users.php like Full Username, etc .Th | May 23, 2022 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Simple Food Website Project.
Media articles that mention a CVE ID that affects a product developed by Simple Food Website Project — matched by CVE ID, not by vendor name.