Tastyigniter is a restaurant management and online ordering platform whose vulnerability exposure concentrates in its core application and centers on web application security issues such as cross-site scripting, improper access control, authorization flaws, and unrestricted file uploads. These weakness classes reflect the authentication and input-handling demands typical of web-facing food-service and e-commerce platforms. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tastyigniter over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-61417HIGH Cross-Site Scripting (XSS) vulnerability exists in TastyIgniter 3.7.7, affecting the /admin/media_manager component. Attackers can upload a malicious SVG file containing JavaScript | Oct 20, 2025 | 8.8 | 28 | NO | NO |
CVE-2021-38699MEDIUM TastyIgniter 3.0.7 allows XSS via /account, /reservation, /admin/dashboard, and /admin/system_logs. | Aug 15, 2021 | 5.4 | 24 | NO | NO |
CVE-2024-44313HIGH TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the invoice() function within Orders.php which allows unauthorized users to access and generate invoices du | Mar 18, 2025 | 8.1 | 22 | NO | NO |
CVE-2022-38256MEDIUM TastyIgniter v3.5.0 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | Sep 8, 2022 | 5.4 | 21 | NO | NO |
CVE-2024-44314MEDIUM TastyIgniter 3.7.6 contains an Incorrect Access Control vulnerability in the Orders Management System, allowing unauthorized users to update order statuses. The issue occurs in the | Mar 18, 2025 | 6.5 | 19 | NO | NO |
CVE-2022-23378MEDIUM A Cross-Site Scripting (XSS) vulnerability exists within the 3.2.2 version of TastyIgniter. The "items%5B0%5D%5Bpath%5D" parameter of a request made to /admin/allergens/edit/1 is v | Feb 9, 2022 | 5.4 | 19 | NO | NO |
CVE-2022-0602MEDIUM Cross-site Scripting (XSS) - DOM in GitHub repository tastyigniter/tastyigniter prior to 3.3.0. | Apr 5, 2022 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tastyigniter.
Media articles that mention a CVE ID that affects a product developed by Tastyigniter — matched by CVE ID, not by vendor name.