Bowo's vulnerability profile centers on a small portfolio of administrative and development-oriented tools, including its system dashboard, debug log manager, and code explorer, which expose internal infrastructure and sensitive workflows. The recurring weakness classes—missing authorization controls, cross-site scripting, cross-site request forgery, sensitive information exposure, and path traversal—reflect the access-control and input-handling demands of management interfaces, and the vendor's disclosures tend to acquire public exploit code. Defenders should prioritize restricting access to these administrative tools and applying updates promptly; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bowo over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-7246MEDIUM The System Dashboard WordPress plugin before 2.8.10 does not sanitize and escape some parameters, which could allow administrators in multisite WordPress configurations to perform | Mar 20, 2024 | 5.4 | 27 | NO | YES |
CVE-2024-10708MEDIUM The System Dashboard WordPress plugin before 2.8.15 does not validate user input used in a path, which could allow high privilege users such as admin to perform path traversal atta | Dec 10, 2024 | 4.9 | 25 | NO | YES |
CVE-2024-35669HIGH Missing Authorization vulnerability in Bowo Debug Log Manager.This issue affects Debug Log Manager: from n/a through 2.3.1. | Jun 9, 2024 | 8.8 | 24 | NO | NO |
CVE-2023-6383HIGH The Debug Log Manager WordPress plugin before 2.3.0 contains a Directory listing vulnerability was discovered, which allows you to download the debug log without authorization and | Jan 8, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-6136HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Bowo Debug Log Manager.This issue affects Debug Log Manager: from n/a through 2.3.0. | Nov 30, 2023 | 7.5 | 22 | NO | NO |
CVE-2025-32613HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Debug Log Manager debug-log-manager allows Stored XSS.This issue affects | Apr 17, 2025 | 7.1 | 19 | NO | NO |
CVE-2024-32582HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Debug Log Manager allows Stored XSS.This issue affects Debug Log Manager: | Apr 18, 2024 | 7.1 | 19 | NO | NO |
CVE-2024-12299MEDIUM The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Filename parameter in all versions up to, and including, 2.8.17 due to insufficien | Jan 30, 2025 | 6.1 | 18 | NO | NO |
CVE-2024-11107MEDIUM The System Dashboard WordPress plugin before 2.8.15 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perfor | Dec 10, 2024 | 6.1 | 18 | NO | NO |
CVE-2023-5816MEDIUM The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading in all versions up to, and including, 1.4.5. This is due to the fact that the plugin does no | Oct 30, 2024 | 4.9 | 17 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bowo.
Media articles that mention a CVE ID that affects a product developed by Bowo — matched by CVE ID, not by vendor name.