The Wedding Planner Project maintains a web-based event-planning application that, despite a narrow product portfolio, ranks prominently among tracked vendors and carries a notable propensity for critical-severity outcomes across its disclosures. Its vulnerability exposure centers on the core wedding-planner product and recurs through input-handling weaknesses including SQL injection, unrestricted file uploads, and insufficient information placeholders, reflecting the data-entry and file-processing demands of web-based planning tools. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wedding Planner Project over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40485CRITICAL Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /package_detail.php. | Sep 26, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-38509CRITICAL Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budget.php. | Sep 19, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-40484CRITICAL Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_edit.php. | Sep 26, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-40483CRITICAL Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /wedding_details.php. | Sep 26, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-41539HIGH Wedding Planner v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /admin/users_add.php. This vulnerability allows attackers to execute arbitrar | Oct 14, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-40404HIGH Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/select.php. | Sep 26, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-40402HIGH Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_assign.php. | Sep 26, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-42229HIGH Wedding Planner v1.0 is vulnerable to Arbitrary code execution via package_edit.php. | Oct 11, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-40403HIGH Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/feature_edit.php. | Sep 26, 2022 | 7.2 | 25 | NO | NO |
CVE-2022-42075CRITICAL Wedding Planner v1.0 is vulnerable to arbitrary code execution. | Oct 7, 2022 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wedding Planner Project.
Media articles that mention a CVE ID that affects a product developed by Wedding Planner Project — matched by CVE ID, not by vendor name.