CVE-2026-4532: medium-severity vulnerability in code-projects Simple Food Ordering System
code-projects Simple Food Ordering System Database Backup food.sql file access
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.9epss 0.7%
exploitation probability
0.7%top 50% of all CVEs
observed exploitation
nono source reports it
A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /food/sql/food.sql of the component Database Backup Handler. The manipulation leads to files or directories accessible. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. It is recommended to change the configuration settings.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Affected products
code-projects · Simple Food Ordering SystemRelated CVEs — code-projects Simple Food Ordering System
In the same product, most dangerous first.
CVE-2025-12378MEDIUMcode-projects Simple Food Ordering System addproduct.php unrestricted uploadEPSS 0.5%CVE-2025-12301MEDIUMcode-projects Simple Food Ordering System editproduct.php unrestricted uploadEPSS 0.5%CVE-2025-11396MEDIUMcode-projects Simple Food Ordering System product.php sql injectionEPSS 0.5%CVE-2026-4533MEDIUMcode-projects Simple Food Ordering System all-tickets.php sql injectionEPSS 0.5%CVE-2025-12300MEDIUMcode-projects Simple Food Ordering System addcategory.php cross site scriptingEPSS 0.4%CVE-2025-12299MEDIUMcode-projects Simple Food Ordering System addproduct.php cross site scriptingEPSS 0.4%