WonderTrader vulnerabilities
4 CVEs tracked
The open-source trading platform WonderTrader appears in recent reports with multiple vulnerabilities, all affecting versions up to 0.9.9. The core issues involve 'enforcement of behavioral workflow' and 'uninitialized variable' flaws in internal components like the Limit Order Book, Pending Order Handler, and TraderDD. Notably, CVE-2026-19208 allows remote exploitation, increasing the risk profile. Defenders should prioritize patching for CVE-2026-19037, CVE-2026-19208, CVE-2026-19212, and CVE-2026-19213, and monitor for manipulation attempts targeting the `FID_JYLB` argument.
Azərbaycanca: WonderTrader açıq mənbəli ticarət platforması son hesabatlarda bir neçə zəifliklə əlaqədar olaraq qeyd olunur. Bütün zəifliklər 0.9.9 versiyasına qədər olan versiyaları əhatə edir və əsasən daxili komponentlərdə (Limit Order Book, Pending Order Handler, TraderDD) 'enforcement of behavioral workflow' və 'uninitialized variable' kimi problemlərə aiddir. Xüsusilə CVE-2026-19208 uzaqdan istismar imkanı ilə seçilir ki, bu da təhlükə səviyyəsini artırır. Müdafiəçilər bu vendorun CVE-2026-19037, CVE-2026-19208, CVE-2026-19212 və CVE-2026-19213 zəifliklərinə qarşı yamaqları tətbiq etməli və xüsusilə `FID_JYLB` arqumenti ilə manipulyasiya cəhdlərini monitorinq etməlidir.
This vendor's CVEs4
This hub is built from skopnix's own reporting on WonderTrader: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.