The Wedding Management System Project maintains a specialized web application for event planning and coordination that, while narrowly scoped as a single product, serves a distributed user base across event-planning organizations. Its vulnerability profile centers durably on application-layer input-handling weaknesses—specifically SQL injection and unrestricted file uploads—that are characteristic of web platforms handling user-supplied data without sufficient validation and sanitization controls. These weakness classes reflect the persistent challenges in securing database queries and file-handling logic across event-management workflows where user input is central to functionality. Defenders deploying this system should prioritize input validation hardening and file-upload restrictions as core defenses, and track the vendor's security updates accordingly; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wedding Management System Project over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29656CRITICAL Wedding Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Wedding-Management/package_detail.php. | May 11, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-30819HIGH In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "photos_edit.php" file. | Jun 2, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-30822HIGH In Wedding Management System v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_profile.php" file. | Jun 2, 2022 | 8.8 | 26 | NO | NO |
CVE-2022-30821HIGH In Wedding Management System v1.0, the editing function of the "Services" module in the background management system has an arbitrary file upload vulnerability in the picture uploa | Jun 2, 2022 | 8.8 | 26 | NO | NO |
CVE-2022-30820HIGH In Wedding Management v1.0, there is an arbitrary file upload vulnerability in the picture upload point of "users_edit.php" file. | Jun 2, 2022 | 8.8 | 26 | NO | NO |
CVE-2022-30835HIGH Wedding Management System v1.0 is vulnerable to SQL Injection. via /Wedding-Management/admin/budget.php?booking_id=. | Jun 2, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-30834HIGH Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_manage_account_details.php?booking_id=31&user_id= | Jun 2, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-29655HIGH An arbitrary file upload vulnerability in the Upload Photos module of Wedding Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | May 11, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-30836HIGH Wedding Management System v1.0 is vulnerable to SQL Injection. via Wedding-Management/admin/select.php. | Jun 2, 2022 | 7.2 | 23 | NO | NO |
CVE-2022-30832HIGH Wedding Management System v1.0 is vulnerable to SQL Injection via /Wedding-Management/admin/client_assign.php?booking=31&user_id=. | Jun 2, 2022 | 7.2 | 23 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wedding Management System Project.
Media articles that mention a CVE ID that affects a product developed by Wedding Management System Project — matched by CVE ID, not by vendor name.