Wowonder is a social-networking platform whose vulnerability profile centers on a single widely deployed application, yet skews strongly toward critical-severity outcomes. The recurring weakness classes—SQL injection, authorization bypass through user-controlled keys, improper access control, and incorrect authorization—reflect the authentication and data-access logic demands of a multi-tenant social platform and have historically recurred across its major releases. Defenders deploying this platform should prioritize patching and apply strict input validation and access-control hardening; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wowonder over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27200CRITICAL In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day. | Jun 11, 2021 | 9.8 | 31 | NO | NO |
CVE-2022-42984CRITICAL WoWonder Social Network Platform 4.1.4 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=search&s=recipients. | Nov 15, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-40405HIGH WoWonder Social Network Platform v4.1.2 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=load-my-blogs. | Nov 15, 2022 | 7.5 | 25 | NO | NO |
CVE-2021-26935HIGH In WoWonder < 3.1, remote attackers can gain access to the database by exploiting a requests.php?f=search-my-followers SQL Injection vulnerability via the event_id parameter. | Mar 18, 2021 | 7.5 | 24 | NO | NO |
CVE-2022-26254MEDIUM WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to arbitrarily change group ID nam | Mar 27, 2022 | 5.3 | 20 | NO | NO |
CVE-2022-1753MEDIUM A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the | May 17, 2022 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wowonder.
Media articles that mention a CVE ID that affects a product developed by Wowonder — matched by CVE ID, not by vendor name.