CVE-2026-14622
HIGHjairiidriss restaurant-website-php-mysql AJAX Endpoint ajax_files missing authentication
Title source: cnaDescription
A vulnerability was found in jairiidriss restaurant-website-php-mysql up to 521428b5b612449df0cf4a5d15ee40cba67f3d35. This vulnerability affects unknown code of the file /admin/ajax_files of the component AJAX Endpoint. Performing a manipulation results in missing authentication. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.
References (6)
Core 6
Core References
Product product
https://github.com/jairiidriss/restaurant-website-php-mysql/
Vdb Entry vdb-entry
VDB-376138 | jairiidriss restaurant-website-php-mysql AJAX Endpoint ajax_files missing authentication
https://vuldb.com/vuln/376138
Signature, Permissions Required signature
permissions-required
VDB-376138 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/376138/cti
Third Party Advisory third-party-advisory
CVE-2026-14622 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-14622
Third Party Advisory third-party-advisory
Submit #845099 | jairiidriss restaurant-website-php-mysql 1.0 jairiidriss Restaurant Website PHP MySQL 1.0 missing authenticat
https://vuldb.com/submit/845099
Exploit exploit
issue-tracking
https://github.com/jairiidriss/restaurant-website-php-mysql/issues/6
Scores
CVSS v3
7.3
EPSS
0.0041
EPSS Percentile
33.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-287
CWE-306
Status
published
Products (1)
jairiidriss/restaurant-website-php-mysql
521428b5b612449df0cf4a5d15ee40cba67f3d35
Published
Jul 04, 2026
Tracked Since
Jul 04, 2026