VYPR

Fishing Reservation System

by Fishing Reservation System

CVEs (2)

  • CVE-2020-37081HigFeb 3, 2026
    risk 0.46cvss 7.1epss 0.00

    Fishing Reservation System 7.5 contains multiple remote SQL injection vulnerabilities in admin.php, cart.php, and calendar.php that allow attackers to inject malicious SQL commands. Attackers can exploit vulnerable parameters like uid, pid, type, m, y, and code to compromise the database management system and web application without user interaction.

  • CVE-2025-7022MedJul 25, 2025
    risk 0.40cvss 6.1epss 0.00

    The My Reservation System WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.