VYPR

Wallpaper Admin

by VIAVIWEB

CVEs (3)

  • CVE-2022-50893CriJan 13, 2026
    risk 0.64cvss 9.8epss 0.01

    VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functionality. Attackers can upload a malicious PHP file through the add_gallery_image.php endpoint to execute arbitrary code on the server.

  • CVE-2022-50892HigJan 13, 2026
    risk 0.53cvss 8.2epss 0.01

    VIAVIWEB Wallpaper Admin 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating login credentials. Attackers can exploit the login page by injecting 'admin' or 1=1-- - payload to gain unauthorized access to the administrative…

  • CVE-2022-50894MedJan 13, 2026
    risk 0.42cvss 6.5epss 0.00

    VIAVIWEB Wallpaper Admin 1.0 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the img_id parameter. Attackers can send GET requests to edit_gallery_image.php with malicious img_id values to…