VYPR
Vendor

WGDashboard

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2026-15734CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary code as root.

  • CVE-2026-15733CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.14

    A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root.

  • CVE-2026-15732CriAug 6, 2026
    risk 0.57cvss 9.8epss 0.00

    A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and retrieve responses.

  • CVE-2026-44343CriMay 12, 2026
    risk 0.57cvss 9.8epss 0.00

    WGDashboard is a dashboard for WireGuard VPN. Prior to 4.3.2, there are critical vulnerabilities affecting WGDashboard that, if exploited, could allow unauthorized parties to access the host file system without authentication. This vulnerability is fixed in 4.3.2.