Web App.Org maintains a narrow, focused product portfolio centered on a single web application, yet this entity ranks among the more prominent in the vulnerability landscape, indicating a heavily represented or widely tracked single product. The vulnerability disclosures associated with the vendor span a substantial volume despite the constrained product scope, suggesting either a long operational history, a widely deployed application, or both. With no distinct weakness-class patterns identified across the disclosures, the exposure appears generalist rather than tied to a particular architectural or implementation flaw family, making individual CVE context and remediation specificity more important than broad product-family hardening. Defenders should track this vendor's advisories carefully given its prominence and the breadth of its CVE history relative to product count; current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Web App.Org over time
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-1628HIGH apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter. | May 17, 2005 | 7.5 | 33 | NO | YES |
CVE-2005-0927HIGH Unknown vulnerability in subs.pl for WebAPP 0.9.9 through 0.9.9.2 has unknown impact and attack vectors, probably involving shell metacharacters or .. sequences. | May 2, 2005 | 10.0 | 25 | NO | NO |
CVE-2004-1742MEDIUM Directory traversal vulnerability in WebAPP 0.9.9 allows remote attackers to view arbitrary files via a .. (dot dot) in the viewcat parameter. | Aug 24, 2004 | 5.0 | 25 | NO | YES |
CVE-2007-1183HIGH WebAPP before 0.9.9.5 allows remote authenticated users to spoof another user's Real Name via whitespace, which has unknown impact and attack vectors. | Mar 2, 2007 | 7.5 | 21 | NO | NO |
CVE-2007-1188HIGH WebAPP before 0.9.9.5 allows remote attackers to submit Search form input that is not checked for (1) composition or (2) length, which has unknown impact, possibly related to "sear | Mar 2, 2007 | 7.5 | 21 | NO | NO |
CVE-2006-1427MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in WebAPP 0.9.9.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) action, (2) id, (3) nu | Mar 28, 2006 | 4.3 | 21 | NO | YES |
CVE-2007-3242HIGH The Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allows remote authenticated users to execute a | Jun 15, 2007 | 7.5 | 20 | NO | NO |
CVE-2007-3419HIGH The editprofile3 function in cgi-bin/cgi-lib/user.pl in web-app.org WebAPP before 0.9.9.7 does not properly check the (1) themes.dat, (2) languages.dat, (3) profession.dat, (4) gen | Jun 26, 2007 | 7.5 | 19 | NO | NO |
CVE-2007-3420HIGH The Random Cookie Password functionality in the loaduser function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 does not clear the (1) username, (2) password, (3) | Jun 26, 2007 | 7.5 | 19 | NO | NO |
CVE-2007-3421HIGH The (1) login, (2) admin profile edit, (3) reminder, (4) edit profile, (5) profile view, (6) gallery view, (7) gallery comment, and (8) gallery feedback capabilities in web-app.org | Jun 26, 2007 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Web App.Org.
Media articles that mention a CVE ID that affects a product developed by Web App.Org — matched by CVE ID, not by vendor name.