VendorsWedding Management System Projectwedding_management_systemall versions
Vulnerabilities

Wedding Management System Project Wedding Management System

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2022-29656
Wedding Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Wedding-Management/package_detail.php.
Published 2022-05-11 · Modified
9.8EPSS 0.009
CVE-2022-30819
In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "photos_edit.php" file.
Published 2022-05-31 · Modified
8.8EPSS 0.012
CVE-2022-30820
In Wedding Management v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_edit.php" file.
Published 2022-05-31 · Modified
8.8EPSS 0.012
CVE-2022-30821
In Wedding Management System v1.0, the editing function of the "Services" module in the background management system has an arbitrary file upload vulnerability in the picture upload point of "package_edit.php" file.
Published 2022-05-31 · Modified
8.8EPSS 0.012
CVE-2022-30822
In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_profile.php" file.
Published 2022-05-31 · Modified
8.8EPSS 0.012
CVE-2022-29655
An arbitrary file upload vulnerability in the Upload Photos module of Wedding Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
Published 2022-05-11 · Modified
7.2EPSS 0.014
CVE-2022-30827
Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\package_edit.php.
Published 2022-05-31 · Modified
7.2EPSS 0.010
CVE-2022-30834
Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_manage_account_details.php?booking_id=31&user_id=
Published 2022-05-31 · Modified
7.2EPSS 0.010
CVE-2022-30833
Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_edit.php?booking=31&user_id=.
Published 2022-05-31 · Modified
7.2EPSS 0.010
CVE-2022-30831
Wedding Management System v1.0 is vulnerable to SQL Injection via Wedding-Management/wedding_details.php.
Published 2022-05-31 · Modified
7.2EPSS 0.010
CVE-2022-30830
Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\feature_edit.php.
Published 2022-05-31 · Modified
7.2EPSS 0.010
CVE-2022-30828
Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\photos_edit.php.
Published 2022-05-31 · Modified
7.2EPSS 0.010
CVE-2022-30826
Wedding Management System v1.0 is vulnerable to SQL Injection via admin\client_assign.php.
Published 2022-05-31 · Modified
7.2EPSS 0.010
CVE-2022-30825
Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\client_edit.php.
Published 2022-05-31 · Modified
7.2EPSS 0.010
CVE-2022-30823
Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\blog_events_edit.php.
Published 2022-05-31 · Modified
7.2EPSS 0.010
CVE-2022-30818
Wedding Management System v1.0 is vulnerable to SQL injection via /Wedding-Management/admin/blog_events_edit.php?id=31.
Published 2022-05-31 · Modified
7.2EPSS 0.010
CVE-2022-30829
Wedding Management System v1.0 is vulnerable to SQL Injection via \admin\users_edit.php.
Published 2022-05-31 · Modified
7.2EPSS 0.010
CVE-2022-30832
Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_assign.php?booking=31&user_id=.
Published 2022-05-31 · Modified
7.2EPSS 0.010
CVE-2022-30835
Wedding Management System v1.0 is vulnerable to SQL Injection. via /Wedding-Management/admin/budget.php?booking_id=.
Published 2022-05-31 · Modified
7.2EPSS 0.010
CVE-2022-30836
Wedding Management System v1.0 is vulnerable to SQL Injection. via Wedding-Management/admin/select.php.
Published 2022-05-31 · Modified
7.2EPSS 0.010