CVE-2026-78198
A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown process
CVSS
7.3
High
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Aug 24, 2026 · Last modified: Aug 24, 2026 · CWE-74 · CWE-89
Not enough EPSS history yet.
A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=add_to_cart. Such manipulation of the argument pid leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-782447.3 HIG—
——0A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file search.php. Performing a manipulation of the argument search/delivery_type/search_price/property_type results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.5hCVE-2026-783178.8 HIG—
——0SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.6hCVE-2026-783168.8 HIG—
——0SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.6hCVE-2026-783158.8 HIG—
——0SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.6hCVE-2026-783148.8 HIG—
——0SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to
remote code execution.6hCVE-2026-77994——
——0Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the loadStyles method of the frontend page model.8h