Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

gamerz — Vulnerabilities & Security Advisories 10

Browse all 10 CVE security advisories affecting gamerz. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Gamerz primarily operates as a gaming platform, facilitating online multiplayer experiences and community interactions. Historically, Gamerz has been susceptible to multiple remote code execution (RCE) vulnerabilities, cross-site scripting (XSS) attacks, and privilege escalation flaws, with nine CVEs documented to date. These vulnerabilities often stem from insufficient input validation and improper access controls in web interfaces and backend services. While no major public security incidents have been widely reported, the consistent pattern of vulnerabilities suggests potential risks to user accounts and platform integrity. The platform's security posture appears to prioritize functionality over robust protection measures, leaving it vulnerable to exploitation.

CVE ID Title CVSS Severity Published
CVE-2026-19794 WP-Stats <= 2.56 - Unauthenticated Stored Cross-Site Scripting — WP-Stats CWE-79 7.2 High 2026-08-14
CVE-2026-2426 WP-DownloadManager <= 1.69 - Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'file' Parameter — WP-DownloadManager CWE-22 6.5 Medium 2026-02-18
CVE-2026-2419 WP-DownloadManager <= 1.69 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'download_path' Parameter — WP-DownloadManager CWE-22 2.7 Low 2026-02-18
CVE-2025-10747 WP-DownloadManager <= 1.68.11 - Authenticated (Admin+) Arbitrary File Upload — WP-DownloadManager CWE-434 7.2 High 2025-09-26
CVE-2025-4799 WP-DownloadManager <= 1.68.10 - Authenticated (Administrator+) Arbitrary File Deletion — WP-DownloadManager CWE-36 7.2 High 2025-06-11
CVE-2025-4798 WP-DownloadManager <= 1.68.10 - Authenticated (Administrator+) Arbitrary File Read — WP-DownloadManager CWE-200 4.9 Medium 2025-06-11
CVE-2024-13426 WP-Polls <= 2.77.2 - Unauthenticated SQL Injection to Stored Cross-Site Scripting — WP-Polls CWE-89 5.4 Medium 2025-01-22
CVE-2011-10006 GamerZ WP-PostRatings wp-postratings.php cross site scripting — WP-PostRatings CWE-79 3.5 Low 2024-04-08
CVE-2022-2941 WP-UserOnline <= 2.88.0 - Authenticated (Admin+) Stored Cross-Site Scripting — WP-UserOnline CWE-79 5.5 Medium 2022-09-06
CVE-2022-2473 WP-UserOnline <= 2.87.6 - Authenticated (Admin+) Stored Cross-Site Scripting — WP-UserOnline CWE-79 5.5 Medium 2022-09-06

This page lists every published CVE security advisory associated with gamerz. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.