Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bowo

First CVE: Nov 30, 2023Active for: 3 yearsTotal CVEs: 18
30.0
VTI Score
Low

Bowo's vulnerability profile centers on a small portfolio of administrative and development-oriented tools, including its system dashboard, debug log manager, and code explorer, which expose internal infrastructure and sensitive workflows. The recurring weakness classes—missing authorization controls, cross-site scripting, cross-site request forgery, sensitive information exposure, and path traversal—reflect the access-control and input-handling demands of management interfaces, and the vendor's disclosures tend to acquire public exploit code. Defenders should prioritize restricting access to these administrative tools and applying updates promptly; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
5.5
Avg CVSS Score
Higher Avg CVSS Score than 23% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bowo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 30, 2023
2 years ago
Most Recent CVE
Apr 17, 2025
463 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-7246MEDIUM
The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform
Mar 20, 20245.427NOYES
CVE-2024-10708MEDIUM
The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high privilege users such as admin to perform path traversal atta
Dec 10, 20244.925NOYES
CVE-2024-35669HIGH
Missing Authorization vulnerability in Bowo Debug Log Manager.This issue affects Debug Log Manager: from n/a through 2.3.1.
Jun 9, 20248.824NONO
CVE-2023-6383HIGH
The Debug Log Manager WordPress plugin before 2.3.0 contains a Directory listing vulnerability was discovered, which allows you to download the debug log without authorization and
Jan 8, 20247.522NONO
CVE-2023-6136HIGH
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Bowo Debug Log Manager.This issue affects Debug Log Manager: from n/a through 2.3.0.
Nov 30, 20237.522NONO
CVE-2025-32613HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Debug Log Manager debug-log-manager allows Stored XSS.This issue affects
Apr 17, 20257.119NONO
CVE-2024-32582HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Debug Log Manager allows Stored XSS.This issue affects Debug Log Manager:
Apr 18, 20247.119NONO
CVE-2024-12299MEDIUM
The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Filename parameter in all versions up to, and including, 2.8.17 due to insufficien
Jan 30, 20256.118NONO
CVE-2024-11107MEDIUM
The System Dashboard WordPress plugin before 2.8.15 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perfor
Dec 10, 20246.118NONO
CVE-2023-5816MEDIUM
The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading in all versions up to, and including, 1.4.5. This is due to the fact that the plugin does no
Oct 30, 20244.917NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
72%
28%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None12 (66.7%)
Unknown0 (0.0%)
Required6 (33.3%)
Privileges Required
Low8 (44.4%)
High2 (11.1%)
None8 (44.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
11.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bowo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bowo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bowo's Products

View all 3 CNAs →

Top CWEs