CVE-2025-55444: Vishalmathur Online Artwork And Fine Arts Project
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts MCA Project 1.0. A remote attacker can inject arbitrary SQL queries, leading to database enumeration and potential remote code execution.
Affected products
- Vishalmathur Online Artwork And Fine Arts Project: version 1.0 only
Published 2025-08-20. Last modified 2026-06-17.