Whatsupgold

Vendor:

First CVE: Oct 20, 2004 · Active for 21 years

57
Total CVEs
Bottom 1%
5.2
Avg CVEs / Year
Bottom 1%
7.5
Avg CVSS
Higher Avg CVSS than 21% of tracked products
3.5%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Whatsupgold over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 20, 2004
21 years ago
Most Recent CVE
Apr 14, 2025
466 days ago

CVE Severity & Scoring

Whatsupgold57 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local1 (1.8%)
Network51 (89.5%)
Unknown5 (8.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low52 (91.2%)
High0 (0.0%)
Unknown5 (8.8%)
User Interaction
None44 (77.2%)
Unknown5 (8.8%)
Required8 (14.0%)
Privileges Required
Low20 (35.1%)
High2 (3.5%)
None30 (52.6%)
Unknown5 (8.8%)

Top CVEs

Signals from CVEs in this product scope (57 CVEs).

57 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated attacker to retrieve the users encrypted password.
Aug 29, 20249.898YESYES
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The WhatsUp.ExportUtilities.Export.GetFileWith
Jun 25, 20249.898YESYES
Buffer overflow in the _maincfgret.cgi script for Ipswitch WhatsUp Gold before 8.03 Hotfix 1 allows remote attackers to execute arbitrary code via a long instancename parameter.
Oct 20, 20047.572NOYES
In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthenticated attacker to achieve t
Jun 25, 20249.867NONO
In Progress Ipswitch WhatsUp Gold 21.0.0 through 21.1.1, and 22.0.0, it is possible for an unauthenticated attacker to invoke an API transaction that would allow them to relay encr
May 11, 20227.567NOYES
In WhatsUp Gold versions released before 2023.1.3, a vulnerability exists in the TestController functionality.  A specially crafted unauthenticated HTTP request can lead to a di
Jun 25, 20247.557NONO
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.
Dec 2, 20249.856NONO
In WhatsUp Gold versions released before 2024.0.0, if the application is configured with only a single user, a SQL Injection vulnerability allows an unauthenticated attacker to ret
Aug 29, 20249.852NOYES
In WhatsUp Gold versions released before 2024.0.1, a SQL Injection vulnerability allows an authenticated low-privileged user (at least Report Viewer permissions required) to achie
Dec 2, 20248.846NONO
In WhatsUp Gold versions released before 2023.1.3, an uncontrolled resource consumption vulnerability exists. A specially crafted unauthenticated HTTP request to the TestController
Jun 25, 20247.544NONO

Exploit Exposure

Signals from CVEs in this product scope (57 CVEs).

CISA KEV
2 CVEs
3.5% of CVEs· Bottom 1%
Metasploit
6 CVEs
10.5% of CVEs· Bottom 1%
Nuclei
3 CVEs
5.3% of CVEs· Bottom 1%
ExploitDB
5 CVEs
8.8% of CVEs· 93rd percentile

Social Chatter

Signals from CVEs in this product scope (57 CVEs).

Media Mentions

Signals from CVEs in this product scope (57 CVEs).

Top CNAs Publishing CVEs For Whatsupgold

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.0326.334.4%01
8.0126.334.4%01
8.026.334.4%01
7.0426.334.4%01
7.0326.334.4%01
7.026.334.4%01
23.1.017.222.4%00
22.0.046.517.1%04
21.1.116.53.9%01
21.1.016.53.9%01
16.319.83.5%01
15.0225.93.4%02
1117.83.5%00