Known Vulnerabilities for products from Wowonder
Listed below are 6 of the newest known vulnerabilities associated with the vendor "Wowonder".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-42984 json | WoWonder Social Network Platform 4.1.4 was discovered to contain a SQL injection vulnerability via the offset parameter at re... | 9.8 - CRITICAL | 2022-11-15 | 2022-11-17 |
| CVE-2022-40405 json | WoWonder Social Network Platform v4.1.2 was discovered to contain a SQL injection vulnerability via the offset parameter at r... | 7.5 - HIGH | 2022-11-15 | 2022-11-17 |
| CVE-2022-26254 json | WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unaut... | 5.3 - MEDIUM | 2022-03-27 | 2022-04-05 |
| CVE-2022-1753 json | A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is respons... | 4.3 - MEDIUM | 2022-05-17 | 2022-05-25 |
| CVE-2021-27200 json | In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The cod... | 9.8 - CRITICAL | 2021-06-11 | 2022-07-12 |
| CVE-2021-26935 json | In WoWonder < 3.1, remote attackers can gain access to the database by exploiting a requests.php?f=search-my-followers SQL In... | 7.5 - HIGH | 2021-03-18 | 2021-03-24 |