Matt Wright's vulnerability profile centers on a small collection of early-stage CGI and web-form utilities, particularly FormMail, WWWBoard, and related script-based applications that saw widespread deployment in the 1990s and 2000s as webmasters built dynamic content without frameworks. The recurring weakness classes—input validation failures and cross-site scripting—reflect the minimal parsing discipline typical of early CGI scripts, where user input handling was often passed directly to page generation or system operations. Public exploit code and proof-of-concept tools have been widely available for these utilities, making them persistent targets for both historical vulnerability research and remediation validation. Defenders maintaining legacy or archived web infrastructure should flag these products as obsolete and prioritize their removal; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Matt Wright over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-1999-1053HIGH guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remote attackers to execute arbitrary commands when guestbook.pl | Sep 13, 1999 | 7.5 | 81 | NO | YES |
CVE-1999-0953HIGH WWWBoard stores encrypted passwords in a password file that is under the web root and thus accessible by remote attackers. | Sep 16, 1999 | 10.0 | 40 | NO | YES |
CVE-1999-1479HIGH The textcounter.pl by Matt Wright allows remote attackers to execute arbitrary commands via shell metacharacters. | Jun 24, 1998 | 10.0 | 40 | NO | YES |
CVE-2000-0411MEDIUM Matt Wright's FormMail CGI script allows remote attackers to obtain environmental variables via the env_report parameter. | May 10, 2000 | 5.0 | 25 | NO | YES |
CVE-1999-1050MEDIUM Directory traversal vulnerability in Matt Wright FormHandler.cgi script allows remote attackers to read arbitrary files via (1) a .. (dot dot) in the reply_message_attach attachmen | Nov 12, 1999 | 5.0 | 25 | NO | YES |
CVE-2001-0937HIGH PGPMail.pl 1.31 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) recipient or (2) pgpuserid parameters. | Nov 30, 2001 | 7.5 | 24 | NO | NO |
CVE-1999-0173MEDIUM FormMail CGI program can be used by web servers other than the host server that the program resides on. | Jan 1, 1997 | 5.0 | 24 | NO | YES |
CVE-2009-1777MEDIUM CRLF injection vulnerability in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response s | May 22, 2009 | 5.0 | 23 | NO | YES |
CVE-2009-1776MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML | May 22, 2009 | 4.3 | 21 | NO | YES |
CVE-2006-1697MEDIUM Cross-site scripting (XSS) vulnerability in Matt Wright Guestbook 2.3.1 allows remote attackers to execute arbitrary web script or HTML via the (1) Your Name, (2) E-Mail, or (3) Co | Apr 11, 2006 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Matt Wright.
Media articles that mention a CVE ID that affects a product developed by Matt Wright — matched by CVE ID, not by vendor name.