Vwar operates a single, narrowly scoped Virtual War product that has accumulated a moderate volume of vulnerability disclosures and occupies a position among the more prominent vendors relative to its portfolio size. The vulnerability footprint is dominated by application-layer input-handling and code-injection weaknesses—including SQL injection, code injection, cross-site scripting, and sensitive-data exposure—reflecting common attack surface risks in web-based gaming or simulation platforms. Notably, this vendor's disclosures frequently acquire public exploit code, suggesting active researcher and threat-actor interest despite the vendor's limited product scope. Defenders relying on Virtual War should prioritize input-validation and output-encoding controls and monitor updates closely; current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vwar over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-5063HIGH SQL injection vulnerability in article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the ratearticleselect parameter. | Oct 8, 2012 | 7.5 | 30 | NO | YES |
CVE-2006-1747HIGH PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter to (1) admin/admin.ph | Apr 12, 2006 | 7.5 | 29 | NO | YES |
CVE-2008-0753HIGH SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the month parameter. | Feb 13, 2008 | 7.5 | 28 | NO | YES |
CVE-2007-4605HIGH PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the vwar_ | Aug 31, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-2312HIGH Multiple SQL injection vulnerabilities in the Virtual War (VWar) 1.5.0 R15 module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the n parameter to extra | Apr 26, 2007 | 7.5 | 28 | NO | YES |
CVE-2006-4142HIGH SQL injection vulnerability in extra/online.php in Virtual War (VWar) 1.5.0 R14 and earlier allows remote attackers to execute arbitrary SQL commands via the n parameter. | Aug 14, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-4010HIGH SQL injection vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: other vector | Aug 7, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-4009MEDIUM Cross-site scripting (XSS) vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter. | Aug 7, 2006 | 4.3 | 21 | NO | YES |
CVE-2010-5067MEDIUM Virtual War (aka VWar) 1.6.1 R2 uses static session cookies that depend only on a user's password, which makes it easier for remote attackers to bypass timeout and logout actions, | Oct 8, 2012 | 6.8 | 20 | NO | NO |
CVE-2006-3139HIGH Multiple SQL injection vulnerabilities in war.php in Virtual War (VWar) 1.5.0 R14 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) showgame, | Jun 22, 2006 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vwar.
Media articles that mention a CVE ID that affects a product developed by Vwar — matched by CVE ID, not by vendor name.