Wampserver is a lightweight, locally oriented Apache-MySQL-PHP stack distribution targeting Windows developers and small deployments, with a narrow product footprint centered on the integrated wampserver package itself. Vulnerabilities affecting this vendor recur through application-layer input-handling and code-generation weaknesses, including cross-site scripting, cross-site request forgery, and code injection, which are characteristic of web-stack software where user input flows directly into rendered pages and server-side logic. The vendor's disclosures tend to acquire public exploit code readily, making advisories actionable for both defensive and offensive purposes. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wampserver over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-8817HIGH Wampserver before 3.1.3 has CSRF in add_vhost.php. | Mar 25, 2018 | 8.8 | 39 | NO | YES |
CVE-2016-10031HIGH WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYSTEM privileges. This could potentially allow an authorized b | Dec 27, 2016 | 7.5 | 36 | NO | YES |
CVE-2018-8732MEDIUM Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the virtual_del parameter. | Mar 19, 2018 | 5.4 | 29 | NO | YES |
CVE-2022-36565HIGH Incorrect access control in the install directory (C:\Wamp64) of Wamp v3.2.6 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in | Aug 30, 2022 | 8.8 | 28 | NO | NO |
CVE-2016-10072HIGH WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify. This could potentially allow an authorized but non-privileged local user to e | Dec 27, 2016 | 7.5 | 25 | NO | NO |
CVE-2019-11517MEDIUM WampServer before 3.1.9 has CSRF in add_vhost.php because the synchronizer pattern implemented as remediation of CVE-2018-8817 was incomplete. An attacker could add/delete any vhos | Jun 10, 2019 | 6.5 | 21 | NO | NO |
CVE-2010-0700MEDIUM Cross-site scripting (XSS) vulnerability in index.php in WampServer 2.0i allows remote attackers to inject arbitrary web script or HTML via the lang parameter. | Feb 23, 2010 | 4.3 | 21 | NO | YES |
CVE-2018-1000848MEDIUM Wampserver version prior to version 3.1.5 contains a Cross Site Scripting (XSS) vulnerability in index.php localhost page that can result in very low. This attack appear to be expl | Dec 20, 2018 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wampserver.
Media articles that mention a CVE ID that affects a product developed by Wampserver — matched by CVE ID, not by vendor name.