Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

WhatsUp Gold — Vulnerabilities & Security Advisories 37

All 37 CVE vulnerabilities found in WhatsUp Gold, with AI-generated Chinese analysis, references, and POCs.

This page documents known weaknesses and security advisories associated with WhatsUp Gold, a network monitoring solution developed by Ipswitch. It serves as a centralized reference for tracking vulnerabilities across different versions of the software, focusing on common vulnerability types such as cross-site scripting, SQL injection, and unauthorized access flaws. The data collected here spans vulnerability reports from 2018 through 2024, reflecting the product’s security landscape during this period of active network management usage and subsequent patch cycles. Readers can use this resource to track Ipswitch’s security advisories and understand how specific weakness classes have impacted WhatsUp Gold over time. By reviewing the aggregated entries, users can look up a product’s vulnerability history to identify recurring issues, assess the effectiveness of past patches, and evaluate the overall risk posture of their deployed instances. This compilation helps administrators and security analysts contextualize individual flaws within the broader ecosystem of network monitoring tools. The information is organized to facilitate quick reference for technical teams conducting impact assessments or planning remediation strategies. It does not provide exhaustive details on every single exploit but rather aggregates publicly disclosed issues to provide a comprehensive overview. This approach allows for a clearer understanding of the security challenges inherent in the product line, enabling more informed decision-making regarding upgrade paths, configuration hardening, and third-party integration risks. The focus remains strictly on factual reporting of disclosed vulnerabilities without speculation or recommendation.

Vendor: Progress Software Corporation

CVE IDTitleCVSSSeverityPublished
CVE-2025-2572 WhatsUp Gold NmConfigurationManager.exe database manipulation vulnerability CWE-287 5.6 Medium2025-04-14
CVE-2024-12105 WhatsUp Gold - SnmpExtendedActiveMonitor path traversal CWE-22 6.5 Medium2024-12-31
CVE-2024-12106 WhatsUp Gold - LDAP configuration interface leading to allowing attacker to configure LDAP settings without authentication CWE-306 9.4 Critical2024-12-31
CVE-2024-12108 WhatsUp Gold - Public API signing key rotation issue CWE-290 9.6 Critical2024-12-31
CVE-2024-8785 WhatsUp Gold Registry Overwrite Remote Code Execution Vulnerability CWE-648 9.8 Critical2024-12-02
CVE-2024-46909 WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability CWE-22 9.8 Critical2024-12-02
CVE-2024-46905 WhatsUp Gold GetOrderByClause SQL Injection Privilege Escalation Vulnerability CWE-89 8.8 High2024-12-02
CVE-2024-46906 WhatsUp Gold GetSqlWhereClause SQL Injection Privilege Escalation Vulnerability CWE-89 8.8 High2024-12-02
CVE-2024-46907 WhatsUp Gold GetFilterCriteria SQL Injection Privilege Escalation Vulnerability CWE-89 8.8 High2024-12-02
CVE-2024-46908 WhatsUp Gold GetFilterCriteria SQL Injection Privilege Escalation Vulnerability CWE-89 8.8 High2024-12-02
CVE-2024-7763 WhatsUp Gold getReport Missing Authentication Authentication Bypass Vulnerability CWE-287 9.8 Critical2024-10-24
CVE-2024-6672 WhatsUp Gold getMonitorJoin SQL Injection Privilege Escalation Vulnerability CWE-89 8.8 High2024-08-29
CVE-2024-6671 WhatsUp Gold GetStatisticalMonitorList SQL Injection Authentication Bypass Vulnerability CWE-89 9.8 Critical2024-08-29
CVE-2024-6670 WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability CWE-89 9.8 Critical2024-08-29
CVE-2024-5019 WhatsUp Gold LoadCSSUsingBasePath Directory Traversal Information Disclosure Vulnerability CWE-22 5.3 Medium2024-06-25
CVE-2024-5018 WhatsUp Gold LoadUsingBasePath Directory Traversal Information Disclosure Vulnerability CWE-22 5.3 Medium2024-06-25
CVE-2024-5017 WhatsUp Gold AppProfileImport path traversal vulnerability CWE-22 6.5 Medium2024-06-25
CVE-2024-5016 WhatsUp Gold OnMessage Deserialization of Untrusted Data Remote Code Execution Vulnerability CWE-502 7.2 High2024-06-25
CVE-2024-5015 WhatsUp Gold SessionControler Server-Side Request Forgery Information Disclosure Vulnerability CWE-918 7.1 High2024-06-25
CVE-2024-5014 WhatsUp Gold GetASPReport Server-Side Request Forgery Information Disclosure CWE-918 7.1 High2024-06-25
CVE-2024-5013 WhatsUp Gold InstallController Denial-of-Service Vulnerability CWE-400 7.5 High2024-06-25
CVE-2024-5012 WhatsUp Gold Missing Authentication GetWindowsCredential Information Disclosure Vulnerability CWE-287 8.6 High2024-06-25
CVE-2024-5011 WhatsUp Gold TestController Chart denial of service vulnerability CWE-400 7.5 High2024-06-25
CVE-2024-5010 WhatsUp Gold TestController multiple information disclosure vulnerabilities CWE-200 7.5 High2024-06-25
CVE-2024-5009 WhatsUp Gold SetAdminPassword Improper Access Control Privilege Escalation Vulnerability CWE-269 8.4 High2024-06-25
CVE-2024-5008 WhatsUp Gold APM Unrestricted File Upload Remote Code Execution Vulnerability CWE-434 8.8 High2024-06-25
CVE-2024-4885 WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability CWE-22 9.8 Critical2024-06-25
CVE-2024-4884 WhatsUp Gold CommunityController Unrestricted File Upload Remote Code Execution Vulnerability CWE-77 9.8 Critical2024-06-25
CVE-2024-4883 WhatsUp Gold WriteDataFile Directory Traversal Remote Code Execution Vulnerability CWE-77 9.8 Critical2024-06-25
CVE-2024-4562 WhatsUp Gold Server-Side Request Forgery Information Disclosure Vulnerability via HttpMonitorSettings CWE-918 5.4 Medium2024-05-14

All 37 known CVE vulnerabilities affecting WhatsUp Gold with full Chinese analysis, references, and POCs where available.