Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wampserver

First CVE: Feb 23, 2010Active for: 16 yearsTotal CVEs: 8

Wampserver is a lightweight, locally oriented Apache-MySQL-PHP stack distribution targeting Windows developers and small deployments, with a narrow product footprint centered on the integrated wampserver package itself. Vulnerabilities affecting this vendor recur through application-layer input-handling and code-generation weaknesses, including cross-site scripting, cross-site request forgery, and code injection, which are characteristic of web-stack software where user input flows directly into rendered pages and server-side logic. The vendor's disclosures tend to acquire public exploit code readily, making advisories actionable for both defensive and offensive purposes. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wampserver over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 23, 2010
16 years ago
Most Recent CVE
Aug 30, 2022
1,424 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-8817HIGH
Wampserver before 3.1.3 has CSRF in add_vhost.php.
Mar 25, 20188.839NOYES
CVE-2016-10031HIGH
WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYSTEM privileges. This could potentially allow an authorized b
Dec 27, 20167.536NOYES
CVE-2018-8732MEDIUM
Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the virtual_del parameter.
Mar 19, 20185.429NOYES
CVE-2022-36565HIGH
Incorrect access control in the install directory (C:\Wamp64) of Wamp v3.2.6 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in
Aug 30, 20228.828NONO
CVE-2016-10072HIGH
WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify. This could potentially allow an authorized but non-privileged local user to e
Dec 27, 20167.525NONO
CVE-2019-11517MEDIUM
WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-2018-8817 was incomplete. An attacker could add/delete any vhos
Jun 10, 20196.521NONO
CVE-2010-0700MEDIUM
Cross-site scripting (XSS) vulnerability in index.php in WampServer 2.0i allows remote attackers to inject arbitrary web script or HTML via the lang parameter.
Feb 23, 20104.321NOYES
CVE-2018-1000848MEDIUM
Wampserver version prior to version 3.1.5 contains a Cross Site Scripting (XSS) vulnerability in index.php localhost page that can result in very low. This attack appear to be expl
Dec 20, 20186.120NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
50%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local2 (25.0%)
Network5 (62.5%)
Unknown1 (12.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (62.5%)
High2 (25.0%)
Unknown1 (12.5%)
User Interaction
None1 (12.5%)
Unknown1 (12.5%)
Required6 (75.0%)
Privileges Required
Low4 (50.0%)
High0 (0.0%)
None3 (37.5%)
Unknown1 (12.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
50.0% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wampserver.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wampserver — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wampserver's Products

View all 1 CNAs →

Top CWEs