Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wowonder

First CVE: Mar 18, 2021Active for: 5 yearsTotal CVEs: 6

Wowonder is a social-networking platform whose vulnerability profile centers on a single widely deployed application, yet skews strongly toward critical-severity outcomes. The recurring weakness classes—SQL injection, authorization bypass through user-controlled keys, improper access control, and incorrect authorization—reflect the authentication and data-access logic demands of a multi-tenant social platform and have historically recurred across its major releases. Defenders deploying this platform should prioritize patching and apply strict input validation and access-control hardening; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wowonder over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 18, 2021
5 years ago
Most Recent CVE
Nov 15, 2022
1,347 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-27200CRITICAL
In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. The code parameter is easily predicted from the time of day.
Jun 11, 20219.831NONO
CVE-2022-42984CRITICAL
WoWonder Social Network Platform 4.1.4 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=search&s=recipients.
Nov 15, 20229.830NONO
CVE-2022-40405HIGH
WoWonder Social Network Platform v4.1.2 was discovered to contain a SQL injection vulnerability via the offset parameter at requests.php?f=load-my-blogs.
Nov 15, 20227.525NONO
CVE-2021-26935HIGH
In WoWonder < 3.1, remote attackers can gain access to the database by exploiting a requests.php?f=search-my-followers SQL Injection vulnerability via the event_id parameter.
Mar 18, 20217.524NONO
CVE-2022-26254MEDIUM
WoWonder The Ultimate PHP Social Network Platform v4.0.0 was discovered to contain an access control issue which allows unauthenticated attackers to arbitrarily change group ID nam
Mar 27, 20225.320NONO
CVE-2022-1753MEDIUM
A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the
May 17, 20224.314NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
33%
33%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None5 (83.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wowonder.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wowonder — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wowonder's Products

View all 2 CNAs →

Top CWEs