SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19916

LOW · CVSS 3.5 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The Online Food Order System 1.0 contains a cross-site scripting vulnerability in the edit_food_items.php file, specifically affecting the manipulation of the 'dname' argument. This flaw allows remote attackers to execute malicious scripts in the context of a user's session, potentially compromising sensitive information. Organizations using this system should prioritize patching this vulnerability to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-19916
Severity
LOW
CVSS
3.5
EPSS
0.20%

Original NVD Description

A vulnerability was detected in code-projects Online Food Order System 1.0. The affected element is an unknown function of the file edit_food_items.php. Performing a manipulation of the argument dname results in cross site scripting. Remote exploitation of the attack is possible. The exploit is now public and may be used.