Vulnerabilities
12 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-41539 +1 in the same advisory: …41538 | Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /admin/users_add.php. Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /admin/users_add.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. NVD description · AI analysis pending | 8.8 | 1% | PoC |
| — | |
| CVE-2022-42034 +1 in the same advisory: …42229 | Wedding Planner v1.0 is vulnerable to arbitrary code execution via users_profile.php. Wedding Planner v1.0 is vulnerable to arbitrary code execution via users_profile.php. NVD description · AI analysis pending | 8.8 | 1% | PoC |
| — | |
| CVE-2022-42075 | Wedding Planner v1.0 is vulnerable to arbitrary code execution. Wedding Planner v1.0 is vulnerable to arbitrary code execution. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2022-40484 | Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_edit.php. Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_edit.php. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — | |
| CVE-2022-38509 | Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budget.php. Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budget.php. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — |