A SQL injection vulnerability has been identified in SourceCodester Simple Online Food Ordering System version 1.0. The vulnerability exists in the /admin/ajax.php?action=delete_category file, where manipulation of the 'ID' argument allows SQL injection attacks. The flaw can be exploited remotely without requiring physical access to the system. A public exploit has already been disclosed, increasing the risk of active exploitation. The vulnerability was reported via VulDB and GitHub, and is tracked as CVE-2026-76998. Attackers could potentially use this to manipulate or extract database contents. The issue affects the admin panel's category deletion functionality. No patch or mitigation details are mentioned in the article.