Web Wiz Forums
Vendor:
First CVE: Dec 31, 2004 · Active for 21 years
5
Total CVEs
Bottom 1%
1.3
Avg CVEs / Year
Bottom 1%
5.5
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Web Wiz Forums over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Feb 22, 2026
156 days ago
CVE Severity & Scoring
Web Wiz Forums5 CVEs
80%
20%
All CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (20.0%)
Unknown4 (80.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (20.0%)
High0 (0.0%)
Unknown4 (80.0%)
User Interaction
None1 (20.0%)
Unknown4 (80.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (20.0%)
Unknown4 (80.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25442HIGH Web Wiz Forums 12.01 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the PF parameter. At | Feb 22, 2026 | 7.5 | 26 | NO | NO |
CVE-2008-0466MEDIUM Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authentication, which allows remote attack | Jan 29, 2008 | 5.0 | 24 | NO | YES |
CVE-2008-0480MEDIUM Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\\\ in the | Jan 29, 2008 | 5.0 | 23 | NO | YES |
CVE-2006-0175MEDIUM Cross-site scripting (XSS) vulnerability in search_form.asp in Web Wiz Forums 6.34 allows remote attackers to inject arbitrary web script or HTML via the search parameter. | Jan 11, 2006 | 4.3 | 22 | NO | YES |
CVE-2004-2733MEDIUM Web Wiz Forums 7.7a uses invalid logic to determine user privileges, which allows remote attackers to (1) block arbitrary IP addresses via pop_up_ip_blocking.asp or (2) modify topi | Dec 31, 2004 | 5.8 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
60.0% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Web Wiz Forums
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.07 | 1 | 5.0 | 4.9% | 0 | 1 |
| 7.7 | 1 | 5.8 | 1.5% | 0 | 0 |
| 6.34 | 1 | 4.3 | 3.4% | 0 | 1 |
| 12.01 | 1 | 7.5 | 0.4% | 0 | 0 |