← Back

Wowonder

wowonder

Vendor: Wowonder • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wowonder
1Wowonder
Apr 30, 2025
Nov 15, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
WoWonder Social Network Platform 4.1.4 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=search&s=recipients.
1Wowonder
1Wowonder
Apr 30, 2025
Nov 15, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
WoWonder Social Network Platform v4.1.2 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=load-my-blogs.
1Wowonder
1Wowonder
Nov 21, 2024
May 17, 2022
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the argument group_id allows posting message...Show more
A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the argument group_id allows posting messages in other groups. It is possible to launch the attack remotely but it might require authentication. A video explaining the attack has been disclosed to the public.Show less
1Wowonder
1Wowonder
Nov 21, 2024
Mar 27, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to arbitrarily change group ID names.
1Wowonder
1Wowonder
Nov 21, 2024
Jun 11, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.
1Wowonder
1Wowonder
Nov 21, 2024
Mar 18, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In WoWonder < 3.1, remote attackers can gain access to the database by exploiting a requests.php?f=search-my-followers SQL Injection vulnerability via the event_id parameter.