CVE-2026-5019 | code-projects Simple Food Order System 1.0 Parameter all-orders.php Status sql injection (EUVD-2026-16959)
A vulnerability marked as critical has been reported in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file all-orders.php of the component Parameter Handler. The manipulation of the argument Status leads to sql injection.
This vulnerability is listed as CVE-2026-5019. The attack may be initiated remotely. In addition, an exploit is available.