References http://packetstormsecurity.com/files/167123/Royal-Event-Management-System-1.0-SQL-Injection.html https://github.com/erengozaydin/Royal-Event-Management-System-todate-SQL-Injection-Authenticated https://github.com/advisories/GHSA-r54g-jm5f-4gvj https://www.sourcecodester.com/php/15238/event-management-system-project-php-source-code.html https://www.sourcecodester.com/sites/default/files/download/oretnom23/Royal%20Event.zip https://nvd.nist.gov/vuln/detail/CVE-2022-28080 https://cvefeed.io/vuln/detail/CVE-2022-28080 https://cve.imfht.com/poc_detail/39041619d399513b4a6abbad275948423fdbaad2?lang=en https://www.exploit-db.com/exploits/50934 https://www.exploit-db.com/raw/50934 https://app.opencve.io/cve/?product=event_management_system&vendor=event_management_system_project
Related VulnerabilitiesWordpress Events Calendar插件敏感信息泄露漏洞(CVE-2025-9808)PoCphpjabbers-event-booking-xss: PHPJabbers Event Booking Calendar - Reflected XSSPoCCVE-2025-32614: EventON Lite <= 2.4 - Authenticated Local File InclusionPoCCVE-2026-32583: Webnus Inc. Modern Events Calendar - Broken Access Control安科瑞电气股份有限公司环保用电监管云平台EventyUpLoadPic任意文件上传PoC用友 NC /portal/pt/oacoSchedulerEvents/deleteEvent SQL 注入漏洞PoCwordpress-events-manager-fpd: WordPress Events Manager - Full Path DisclosurePoC福建科立讯通信指挥调度平台 /api/client/event/phoneeventlist.php SQL 注入漏洞PoCCVE-2024-5333: WordPress Events Calendar 6.8.2.1 - Information DisclosurePoCwp-twenty-theme-fpd: WordPress Twenty Seventeen - Full Path DisclosurePoCCVE-2025-9808: The Events Calendar <= 6.15.2 - Information DisclosurePoCwp-the-events-calendar-fpd: WordPress The Events Calendar - Full Path DisclosureWordPress wp-event-solution 插件 /wp-admin/admin-ajax.php 文件读取漏洞(CVE-2025-47445)