CVE-2026-4900: medium-severity vulnerability in code-projects Online Food Ordering System
code-projects Online Food Ordering System localhost.sql privilege escalation
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.9epss 0.5%
exploitation probability
0.5%top 60% of all CVEs
observed exploitation
nono source reports it
A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the file /dbfood/localhost.sql. This manipulation causes files or directories accessible. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. It is advisable to modify the configuration settings.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Affected products
code-projects · Online Food Ordering SystemRelated CVEs — code-projects Online Food Ordering System
In the same product, most dangerous first.
CVE-2026-5157MEDIUMcode-projects Online Food Ordering System Order order.php cross site scriptingEPSS 0.4%CVE-2026-4898MEDIUMcode-projects Online Food Ordering System contact.php cross site scriptingEPSS 0.4%CVE-2026-4844MEDIUMcode-projects Online Food Ordering System Admin Login admin.php sql injectionEPSS 0.4%CVE-2026-4841MEDIUMcode-projects Online Food Ordering System Shopping Cart cart.php sql injectionEPSS 0.4%CVE-2026-4899MEDIUMcode-projects Online Food Ordering System food.php cross site scriptingEPSS 0.4%