Wangl1989's vulnerability profile centers on a focused web-application platform, MySiteForMe, that presents a recurring surface of application-layer and data-handling risks. The disclosures cluster around untrusted deserialization, server-side request forgery, cross-site scripting, SQL injection, and cross-site request forgery—a pattern characteristic of web frameworks with exposure in input validation and session handling—and vulnerabilities affecting this vendor skew strongly toward critical severity. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wangl1989 over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-13136CRITICAL A vulnerability was found in wangl1989 mysiteforme 1.0 and classified as critical. Affected by this issue is the function rememberMeManager of the file src/main/java/com/mysiteform | Jan 5, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-26136CRITICAL A SQL injection vulnerability exists in mysiteforme versions prior to 2025.01.1. | Mar 4, 2025 | 9.8 | 25 | NO | NO |
CVE-2022-29309HIGH mysiteforme v2.2.1 was discovered to contain a Server-Side Request Forgery. | May 24, 2022 | 7.5 | 25 | NO | NO |
CVE-2024-57767HIGH MSFM before v2025.01.01 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /file/download. | Jan 15, 2025 | 8.6 | 24 | NO | NO |
CVE-2024-57766CRITICAL MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/editField. | Jan 15, 2025 | 9.1 | 24 | NO | NO |
CVE-2024-57763CRITICAL MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/addField. | Jan 15, 2025 | 9.1 | 24 | NO | NO |
CVE-2024-13138HIGH A vulnerability was found in wangl1989 mysiteforme 1.0. It has been declared as critical. This vulnerability affects the function upload of the file src/main/java/com/mysiteform/ad | Jan 5, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-57764CRITICAL MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/add. | Jan 15, 2025 | 9.1 | 22 | NO | NO |
CVE-2024-13139HIGH A vulnerability was found in wangl1989 mysiteforme 1.0. It has been rated as critical. This issue affects the function doContent of the file src/main/java/com/mysiteform/admin/cont | Jan 5, 2025 | 8.8 | 22 | NO | NO |
CVE-2024-57765HIGH MSFM before 2025.01.01 was discovered to contain a SQL injection vulnerability via the s_name parameter at table/list. | Jan 15, 2025 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wangl1989.
Media articles that mention a CVE ID that affects a product developed by Wangl1989 — matched by CVE ID, not by vendor name.