Wonko's vulnerability footprint centers on a narrow set of file-transfer and monitoring utilities, with the durable signal centered on access-control and cryptographic-strength weaknesses such as path traversal and weak pseudo-random number generation. Current exploitation activity, severity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wonko over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-58041CRITICAL Smolder versions through 1.51 for Perl uses insecure rand() function for cryptographic functions.
Smolder 1.51 and earlier for Perl uses the rand() function as the default source | Feb 24, 2026 | 9.1 | 30 | NO | NO |
CVE-2009-1407MEDIUM Directory traversal vulnerability in config.php in NotFTP 1.3.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a certain languages[][file] parameter. | Apr 24, 2009 | 6.8 | 27 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wonko.
Media articles that mention a CVE ID that affects a product developed by Wonko — matched by CVE ID, not by vendor name.