Skip to main content

Vendor archive

webwiz CVEs

Beta · best-effort

7 CVEs tagged to vendor webwiz0 Critical, 3 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2019-25442

Published Feb 22, 2026

Web Wiz Forums 12.01 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the PF parameter. A…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-5019

Published Dec 1, 2010

Web Wiz NewsPad stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for dat…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6212

Published Dec 1, 2006

PHP remote file inclusion vulnerability in centre.php in Site News (site_news) 2.00, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0175

Published Jan 11, 2006

Cross-site scripting (XSS) vulnerability in search_form.asp in Web Wiz Forums 6.34 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2733

Published Dec 31, 2004

Web Wiz Forums 7.7a uses invalid logic to determine user privileges, which allows remote attackers to (1) block arbitrary IP addresses via pop_up_ip_blocking.asp or (2) modify top…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1