---
id: CVE-2026-92385
title: >-
  A vulnerability has been found in SourceCodester Online Food Ordering System
  1.0
summary: >-
  A vulnerability has been found in SourceCodester Online Food Ordering System
  1.0. The affected element is an unknown function of the file
  /admin/update_category.php of the component Category Update. The manipulation
  leads to cross site s…
severity: low
cvss: 2.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: SourceCodester
product: Online Food Ordering System
affected:
  - online_food_ordering_system 1.0
published: '2026-09-16'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T17:17:29.753'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92385'
references:
  - url: >-
      https://drive.google.com/file/d/1nwr_EravSW9f62itP8sS6OpE3rqRDVkn/view?usp=sharing
    label: cna@vuldb.com
  - url: >-
      https://gist.github.com/MuhammadAmmar-Hacker/d0426a562fe0fa59efbfe7d45778ed27
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-92385'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/939727'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/405522'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/405522/cti'
    label: cna@vuldb.com
  - url: 'https://www.sourcecodester.com/'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00355
epssPercentile: 0.29262
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-22T16:05:47.220563Z'
ingestedAt: '2026-09-16T15:58:38.777Z'
---

## Overview

A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/update_category.php of the component Category Update. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
