
Public VulDB reports three remotely reachable SQL injection flaws (CVE-2026-76048, CVE-2026-76049, CVE-2026-76050) in SourceCodester Simple Online Food Ordering System 1.0 on /admin/ajax.php, rated critical with exploits said to be available. https://cyberresearch.us/research/sourcecodester-simple-online-food-ordering-2026-08/
Post summary
Three critical, remotely reachable SQL injection flaws were disclosed in SourceCodester Simple Online Food Ordering System 1.0, with mentions that exploits may exist but no details on active attacks, patches, or PoCs.
