SQL Injection Vulnerability in Simple Food Order System by Code-Projects
CVE-2026-26712
9.8CRITICAL
What is CVE-2026-26712?
The Simple Food Order System version 1.0 by Code-Projects is susceptible to SQL Injection attacks through the /food/view-ticket-admin.php file. This vulnerability allows attackers to execute arbitrary SQL queries, potentially leading to unauthorized data access and manipulation. Proper input validation and sanitization measures must be implemented to mitigate the risk associated with this vulnerability.
