Webwork encompasses a niche portfolio centered on educational online homework and assessment systems, alongside related program generation tooling. The observed vulnerability surface reflects the vendor's application and scripting context, with signals clustering around general input and logic handling issues. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webwork over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-6629HIGH lib/WeBWorK/PG/Translator.pm in WeBWorK Program Generation (PG) Language before 2.3.1 uses an insufficiently restrictive regular expression to determine valid macro filenames, whic | Dec 18, 2006 | 7.5 | 19 | NO | NO |
CVE-2006-0446MEDIUM Unspecified vulnerability in WeBWorK 2.1.3 and 2.2-pre1 allows remote privileged attackers to execute arbitrary commands as the web server via unknown attack vectors. | Jan 27, 2006 | 6.5 | 19 | NO | NO |
CVE-2006-2839MEDIUM Directory traversal vulnerability in PG Problem Editor module (PGProblemEditor.pm) in WeBWorK Online Homework Delivery System 2.2.0 and earlier allows remote attackers to read and | Jun 6, 2006 | 6.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webwork.
Media articles that mention a CVE ID that affects a product developed by Webwork — matched by CVE ID, not by vendor name.