Wuzly's vulnerability footprint concentrates in its single web application product, with a consistent signal centered on web-tier input-handling and request-validation issues including cross-site scripting, SQL injection, cross-site request forgery, and path traversal. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wuzly over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-3839HIGH The administration functionality in Wuzly 2.0 allows remote attackers to bypass authentication by setting the dXNlcm5hbWU cookie. | Dec 24, 2011 | 7.5 | 23 | NO | NO |
CVE-2011-3838HIGH Multiple SQL injection vulnerabilities in Wuzly 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) u parameter to fp.php, (2) epage parameter to newpage.php, | Dec 24, 2011 | 7.5 | 23 | NO | NO |
CVE-2011-3837MEDIUM Directory traversal vulnerability in blog_system/data_functions.php in Wuzly 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the preview parameter to inde | Dec 24, 2011 | 6.8 | 21 | NO | NO |
CVE-2011-3836MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Wuzly 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) add an administr | Dec 24, 2011 | 6.8 | 21 | NO | NO |
CVE-2011-3835MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Wuzly 2.0 allow remote attackers to inject arbitrary web script or HTML via the Referer header to (1) admin/login.php and (2) | Dec 24, 2011 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wuzly.
Media articles that mention a CVE ID that affects a product developed by Wuzly — matched by CVE ID, not by vendor name.