CVE-2022-22909: Digitaldruid Hoteldruid

High severity, CVSS 8.8. EPSS: 45.4% chance of exploitation in the next 30 days.

HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payload into the name field under the Create New Room module.

Affected products

Published 2022-03-03. Last modified 2026-06-17.