---
id: CVE-2025-11600
title: >-
  A security vulnerability has been detected in code-projects Simple Food
  Ordering System 1.0
summary: >-
  A security vulnerability has been detected in code-projects Simple Food
  Ordering System 1.0. Affected is an unknown function of the file
  editcategory.php. Such manipulation of the argument cname leads to sql
  injection. It is possible to …
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
  - CWE-89
vendor: fabian
product: simple_food_ordering_system
affected:
  - simple_food_ordering_system = 1.0
published: '2025-10-11'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11600'
references:
  - url: 'https://code-projects.org/'
    label: cna@vuldb.com
  - url: 'https://github.com/zzonce/cve/issues/1'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.327921'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.327921'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.671913'
    label: cna@vuldb.com
  - url: 'https://github.com/zzonce/cve/issues/1'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00335
epssPercentile: 0.24782
ingestedAt: '2026-10-08T13:42:55.110Z'
---

## Overview

A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Affected is an unknown function of the file editcategory.php. Such manipulation of the argument cname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.

## Affected

- `simple_food_ordering_system = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
