Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Vwar

First CVE: Dec 31, 2005Active for: 21 yearsTotal CVEs: 22
45.9
VTI Score
High

Vwar operates a single, narrowly scoped Virtual War product that has accumulated a moderate volume of vulnerability disclosures and occupies a position among the more prominent vendors relative to its portfolio size. The vulnerability footprint is dominated by application-layer input-handling and code-injection weaknesses—including SQL injection, code injection, cross-site scripting, and sensitive-data exposure—reflecting common attack surface risks in web-based gaming or simulation platforms. Notably, this vendor's disclosures frequently acquire public exploit code, suggesting active researcher and threat-actor interest despite the vendor's limited product scope. Defenders relying on Virtual War should prioritize input-validation and output-encoding controls and monitor updates closely; current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
3.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Vwar over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2005
20 years ago
Most Recent CVE
Oct 8, 2012
5,037 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-5063HIGH
SQL injection vulnerability in article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the ratearticleselect parameter.
Oct 8, 20127.530NOYES
CVE-2006-1747HIGH
PHP remote file inclusion vulnerability in Virtual War (VWar) 1.5.0 allows remote attackers to execute arbitrary PHP code via a URL in the vwar_root parameter to (1) admin/admin.ph
Apr 12, 20067.529NOYES
CVE-2008-0753HIGH
SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the month parameter.
Feb 13, 20087.528NOYES
CVE-2007-4605HIGH
PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the vwar_
Aug 31, 20077.528NOYES
CVE-2007-2312HIGH
Multiple SQL injection vulnerabilities in the Virtual War (VWar) 1.5.0 R15 module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the n parameter to extra
Apr 26, 20077.528NOYES
CVE-2006-4142HIGH
SQL injection vulnerability in extra/online.php in Virtual War (VWar) 1.5.0 R14 and earlier allows remote attackers to execute arbitrary SQL commands via the n parameter.
Aug 14, 20067.528NOYES
CVE-2006-4010HIGH
SQL injection vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: other vector
Aug 7, 20067.528NOYES
CVE-2006-4009MEDIUM
Cross-site scripting (XSS) vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.
Aug 7, 20064.321NOYES
CVE-2010-5067MEDIUM
Virtual War (aka VWar) 1.6.1 R2 uses static session cookies that depend only on a user's password, which makes it easier for remote attackers to bypass timeout and logout actions,
Oct 8, 20126.820NONO
CVE-2006-3139HIGH
Multiple SQL injection vulnerabilities in war.php in Virtual War (VWar) 1.5.0 R14 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) s, (2) showgame,
Jun 22, 20067.520NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
55%
45%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown22 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown22 (100.0%)
User Interaction
None0 (0.0%)
Unknown22 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown22 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
36.4% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Vwar.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Vwar — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Vwar's Products

View all 1 CNAs →

Top CWEs