VYPR
Vendor

Wavelog

Products
1
CVEs
5
Across products
5
Status
Private

Products

1

Recent CVEs

5
  • CVE-2026-54237CriSep 17, 2026
    risk 0.53cvss epss

    Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without an installation lock or permission check. Unsanitized input reaches write_config() and…

  • CVE-2024-48257CriOct 14, 2024
    risk 0.00cvss 9.8epss 0.01

    Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.

  • CVE-2024-48251CriOct 14, 2024
    risk 0.00cvss 9.8epss 0.01

    Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.

  • CVE-2024-48249HigOct 14, 2024
    risk 0.00cvss 7.3epss 0.00

    Wavelog 1.8.5 allows Gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.

  • CVE-2024-8521MedSep 7, 2024
    risk 0.00cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, was found in Wavelog up to 1.8.0. Affected is the function index of the file /qso of the component Live QSO. The manipulation of the argument manual leads to cross site scripting. It is possible to launch the attack remotely.…