CVE-2020-37161: Wedding-Slideshow-Studio Wedding Slideshow Studio

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

Wedding Slideshow Studio 1.36 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the registration name field with malicious payload. Attackers can craft a specially designed payload to trigger remote code execution, demonstrating the ability to run system commands like launching the calculator.

Affected products

Published 2026-02-07. Last modified 2026-06-17.