HOMEVULNERABILITIESVENDORSWedding Planner Project

Wedding Planner ProjectCVEs & Vulnerabilities

12 CVEs affecting Wedding Planner Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

wedding planner 12
CVE-2022-41539HIGH

Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /admin/users_add.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

14 Oct 2022
8.8
CVSS
CVE-2022-41538HIGH

Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /Wedding-Management-PHP/admin/photos_add.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

14 Oct 2022
8.8
CVSS
CVE-2022-42229HIGH

Wedding Planner v1.0 is vulnerable to Arbitrary code execution via package_edit.php.

11 Oct 2022
8.8
CVSS
CVE-2022-42034HIGH

Wedding Planner v1.0 is vulnerable to arbitrary code execution via users_profile.php.

11 Oct 2022
8.8
CVSS
CVE-2022-42075CRITICAL

Wedding Planner v1.0 is vulnerable to arbitrary code execution.

7 Oct 2022
9.8
CVSS
CVE-2022-40485CRITICAL

Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /package_detail.php.

26 Sep 2022
9.8
CVSS
CVE-2022-40484CRITICAL

Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_edit.php.

26 Sep 2022
9.8
CVSS
CVE-2022-40483CRITICAL

Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /wedding_details.php.

26 Sep 2022
9.8
CVSS
CVE-2022-40404HIGH

Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/select.php.

26 Sep 2022
8.8
CVSS
CVE-2022-40403HIGH

Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/feature_edit.php.

26 Sep 2022
7.2
CVSS
CVE-2022-40402HIGH

Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_assign.php.

26 Sep 2022
8.8
CVSS
CVE-2022-38509CRITICAL

Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budget.php.

20 Sep 2022
9.8
CVSS
← PrevPage 1 / 1Next →