CVE Tools

Web-app-org

32 CVEs tracked since 2007. Since Feb 2007, none of them reached CISA KEV.

Web-app-org CVEs per month

Feb 2007 to Jun 2007. Point at a month, or focus the strip and use the arrow keys.
Web-app-org CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2007-02150
2007-0320
2007-0450
2007-05null or fewer
2007-06100

Products

The products that kept showing up in Web-app-org's monthly top three, with their CVEs summed over those months.

  1. Webapp324 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Web-app-org.

  1. CVE-2007-3417Multiple cross-site scripting (XSS) vulnerabilities in cgi-bin/cgi-lib/search.pl in web-app.org WebAPP before 0.9.9.7 allow remote attackers to inject arbitrary web script or HTML via a search stri...4.3
  2. CVE-2007-3421The (1) login, (2) admin profile edit, (3) reminder, (4) edit profile, (5) profile view, (6) gallery view, (7) gallery comment, and (8) gallery feedback capabilities in web-app.org WebAPP before 0....7.5
  3. CVE-2007-3422The getcgi function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 attempts to parse query strings that contain (1) non-printing characters, (2) certain printing characters that do...7.5
  4. CVE-2007-3420The Random Cookie Password functionality in the loaduser function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 does not clear the (1) username, (2) password, (3) usertheme, and (...7.5
  5. CVE-2007-3424The moveim function in cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the tocat parameter as a subdirectory name when moving an instant message, which has unknown impac...7.5
  6. CVE-2007-3423cgi-bin/cgi-lib/instantmessage.pl in web-app.org WebAPP before 0.9.9.7 uses the From field of an instant message as the beginning of the .dat file name when the (1) imview2 or (2) imview3 function ...7.5
  7. CVE-2007-3418The displaypost function in cgi-bin/cgi-lib/forum_display.pl in web-app.org WebAPP before 0.9.9.7 does not display usernames in conjunction with real names, which makes it easier for remote authent...6.5
  8. CVE-2007-3416Multiple cross-site request forgery (CSRF) vulnerabilities in the administration of (1) polls, (2) profiles, (3) IP bans, and (4) forums in (a) web-app.org WebAPP 0.8 through 0.9.9.6; and (b) web-a...5.0
  9. CVE-2007-3419The editprofile3 function in cgi-bin/cgi-lib/user.pl in web-app.org WebAPP before 0.9.9.7 does not properly check the (1) themes.dat, (2) languages.dat, (3) profession.dat, (4) gen.dat, (5) marstat...7.5
  10. CVE-2007-3242The Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allows remote authenticated users to execute arbitrary commands...7.5
  11. CVE-2007-1832web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to upload certain files (1) via a crafted filename or (2) by "using percent encoding in forms."5.0
  12. CVE-2007-1831web-app.org WebAPP before 0.9.9.6 allows remote authenticated users to open files and write "wrong data" via a crafted QUERY_STRING.6.0
  13. CVE-2007-1828Multiple cross-site scripting (XSS) vulnerabilities in web-app.org WebAPP before 0.9.9.6 allow remote authenticated users to inject arbitrary web script or HTML via (1) the QUERY_STRING correspondi...3.5
  14. CVE-2007-1827Multiple unspecified vulnerabilities in form input validation in web-app.org WebAPP before 0.9.9.6 allow remote authenticated users to corrupt data files, gain access to private files, and execute ...6.0
  15. CVE-2007-1830Unspecified vulnerability in the Username Hijacking Patch 20070312 for web-app.org WebAPP 0.9.9.6 allows remote attackers to obtain administrative access via unknown vectors, related to "something ...4.3

The record

Peak rank
#4 in Feb 2007
Busiest month shown
Feb 2007, 15 CVEs
Months with a KEV entry
0 since Feb 2007
Monthly snapshots
4 since 2007
Web-app-org's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store