Webapp
Vendor:
First CVE: Aug 24, 2004 · Active for 21 years
36
Total CVEs
More Total CVEs than 97% of tracked products
9.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Webapp over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 24, 2004
21 years ago
Most Recent CVE
Jun 26, 2007
6,968 days ago
CVE Severity & Scoring
Webapp36 CVEs
61%
36%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown36 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown36 (100.0%)
User Interaction
None0 (0.0%)
Unknown36 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown36 (100.0%)
Top CVEs
Signals from CVEs in this product scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-1628HIGH apage.cgi in WebAPP 0.9.9.2.1, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the f parameter. | May 17, 2005 | 7.5 | 33 | NO | YES |
CVE-2005-0927HIGH Unknown vulnerability in subs.pl for WebAPP 0.9.9 through 0.9.9.2 has unknown impact and attack vectors, probably involving shell metacharacters or .. sequences. | May 2, 2005 | 10.0 | 25 | NO | NO |
CVE-2004-1742MEDIUM Directory traversal vulnerability in WebAPP 0.9.9 allows remote attackers to view arbitrary files via a .. (dot dot) in the viewcat parameter. | Aug 24, 2004 | 5.0 | 25 | NO | YES |
CVE-2007-1183HIGH WebAPP before 0.9.9.5 allows remote authenticated users to spoof another user's Real Name via whitespace, which has unknown impact and attack vectors. | Mar 2, 2007 | 7.5 | 21 | NO | NO |
CVE-2007-1188HIGH WebAPP before 0.9.9.5 allows remote attackers to submit Search form input that is not checked for (1) composition or (2) length, which has unknown impact, possibly related to "sear | Mar 2, 2007 | 7.5 | 21 | NO | NO |
CVE-2006-1427MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in WebAPP 0.9.9.3.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) action, (2) id, (3) nu | Mar 28, 2006 | 4.3 | 21 | NO | YES |
CVE-2007-3242HIGH The Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allows remote authenticated users to execute a | Jun 15, 2007 | 7.5 | 20 | NO | NO |
CVE-2007-3419HIGH The editprofile3 function in cgi-bin/cgi-lib/user.pl in web-app.org WebAPP before 0.9.9.7 does not properly check the (1) themes.dat, (2) languages.dat, (3) profession.dat, (4) gen | Jun 26, 2007 | 7.5 | 19 | NO | NO |
CVE-2007-3420HIGH The Random Cookie Password functionality in the loaduser function in cgi-bin/cgi-lib/subs.pl in web-app.org WebAPP before 0.9.9.7 does not clear the (1) username, (2) password, (3) | Jun 26, 2007 | 7.5 | 19 | NO | NO |
CVE-2007-3421HIGH The (1) login, (2) admin profile edit, (3) reminder, (4) edit profile, (5) profile view, (6) gallery view, (7) gallery comment, and (8) gallery feedback capabilities in web-app.org | Jun 26, 2007 | 7.5 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (36 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
8.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (36 CVEs).
Media Mentions
Signals from CVEs in this product scope (36 CVEs).
Top CNAs Publishing CVEs For Webapp
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.9.9.6 | 2 | 5.5 | 0.9% | 0 | 0 |
| 0.9.9.5 | 4 | 6.0 | 1.2% | 0 | 0 |
| 0.9.9.4 | 12 | 5.8 | 1.1% | 0 | 0 |
| 0.9.9.3.5 | 2 | 4.8 | 1.5% | 0 | 0 |
| 0.9.9.3.4 | 2 | 4.8 | 1.5% | 0 | 0 |
| 0.9.9.3.3 | 2 | 4.8 | 1.5% | 0 | 0 |
| 0.9.9.3.2 | 12 | 5.5 | 1.3% | 0 | 1 |
| 0.9.9.3.1 | 12 | 5.5 | 1.3% | 0 | 1 |
| 0.9.9.3 | 12 | 5.5 | 1.3% | 0 | 1 |
| 0.9.9.2.2 | 1 | 3.5 | 1.0% | 0 | 0 |
| 0.9.9.2.1 | 13 | 5.7 | 2.0% | 0 | 2 |
| 0.9.9.2 | 14 | 6.0 | 2.0% | 0 | 2 |
| 0.9.9.1 | 13 | 5.9 | 1.3% | 0 | 1 |
| 0.9.9 | 13 | 6.3 | 2.4% | 0 | 2 |