Show filters
37 Total Results
Displaying 21-30 of 37
Sort by:
Attacker Value
Unknown

CVE-2022-40485

Disclosure Date: September 26, 2022 (last updated February 24, 2025)
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /package_detail.php.
Attacker Value
Unknown

CVE-2022-40484

Disclosure Date: September 26, 2022 (last updated February 24, 2025)
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_edit.php.
Attacker Value
Unknown

CVE-2022-40483

Disclosure Date: September 26, 2022 (last updated February 24, 2025)
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /wedding_details.php.
Attacker Value
Unknown

CVE-2022-40404

Disclosure Date: September 26, 2022 (last updated February 24, 2025)
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/select.php.
Attacker Value
Unknown

CVE-2022-40403

Disclosure Date: September 26, 2022 (last updated February 24, 2025)
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/feature_edit.php.
Attacker Value
Unknown

CVE-2022-40402

Disclosure Date: September 26, 2022 (last updated February 24, 2025)
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking parameter at /admin/client_assign.php.
Attacker Value
Unknown

CVE-2022-38509

Disclosure Date: September 19, 2022 (last updated February 24, 2025)
Wedding Planner v1.0 was discovered to contain a SQL injection vulnerability via the booking_id parameter at /admin/budget.php.
Attacker Value
Unknown

CVE-2022-25611

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
Authenticated Stored Cross-Site Scripting (XSS) in Simple Event Planner plugin <= 1.5.4 allows attackers with contributor or higher user roles to inject the malicious script by using vulnerable parameter &custom[add_seg][].
Attacker Value
Unknown

CVE-2022-25612

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
Multiple Authenticated Persistent Cross-Site Scripting (XSS) vulnerabilities in Simple Event Planner WordPress plugin <= 1.5.4 allows user with author or higher user rights inject the malicious code via vulnerable parameters: &custom[event_organiser], &custom[organiser_email], &custom[organiser_contact].
Attacker Value
Unknown

CVE-2019-13027

Disclosure Date: July 12, 2019 (last updated November 27, 2024)
Realization Concerto Critical Chain Planner (aka CCPM) 5.10.8071 has SQL Injection in at least in the taskupdt/taskdetails.aspx webpage via the projectname parameter.
0