Wowonder

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    2
    Critical Level Threats
    2
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2022-40405

    WoWonder Social Network Platform v4.1.2 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=load-my-blogs.

    Last Modified: Apr 30, 2025
    Published: Nov 14, 2022

    CVE-2022-42984

    WoWonder Social Network Platform 4.1.4 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=search&s=recipients.

    Last Modified: Apr 30, 2025
    Published: Nov 14, 2022

    CVE-2022-1753

    WoWonder Group requests.php access control

    Last Modified: Apr 15, 2025
    Published: May 17, 2022

    CVE-2022-26254

    WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to arbitrarily change group ID names.

    Last Modified: Nov 21, 2024
    Published: Mar 27, 2022

    CVE-2021-27200

    In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.

    Last Modified: Nov 21, 2024
    Published: Jun 11, 2021
    Items Per Page
    Wowonder Vulnerabilities & Security CVEs | CVE-DB