CVE-2026-19916: code-projects Online Food Order System edit_food_items.php cross site scripting
Published Aug 15, 2026
·Updated
A vulnerability was detected in code-projects Online Food Order System 1.0. The affected element is an unknown function of the file editfooditems.php. Performing a manipulation of the argument dname results in cross site scripting. Remote exploitation of the attack is possible. The exploit is now public and may be used.
Affected Software
1 affected component
Code-projects Online Food Order System=1.0
Event History
Aug 15, 2026
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-19916?
The severity of CVE-2026-19916 is rated low with a score of 3.5.
2
How do I fix CVE-2026-19916?
To fix CVE-2026-19916, validate and sanitize input on the dname argument in the edit_food_items.php file to prevent cross-site scripting.
3
What type of vulnerability is CVE-2026-19916?
CVE-2026-19916 is a cross-site scripting (XSS) vulnerability.
4
Can CVE-2026-19916 be exploited remotely?
Yes, CVE-2026-19916 can be exploited remotely.
5
Which software is affected by CVE-2026-19916?
CVE-2026-19916 affects version 1.0 of the Code-projects Online Food Order System.