Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2019-25338 DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user a… Dokuwiki No fix yet Fix from $1,6002026-02-12 MEDIUM 5.4 CVE-2023-34408 DokuWiki before 2023-04-04a allows XSS via RSS titles. Dokuwiki 2023-04-04a+ Fix from $1,6002023-06-05 CRITICAL 9.6 CVE-2018-15474 CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remot… Dokuwiki after 2018-04-22a Fix from $2,3002018-09-07 MEDIUM 6.1 CVE-2017-12979 DokuWiki through 2017-02-19c has stored XSS when rendering a malicious language name in a code element, in /inc/parser/xhtml.php. An attacker can cre… Dokuwiki after 2017-02-19c Fix from $1,6002017-08-21 MEDIUM 6.1 CVE-2017-12980 DokuWiki through 2017-02-19c has stored XSS when rendering a malicious RSS or Atom feed, in /inc/parser/xhtml.php. An attacker can create or edit a w… Dokuwiki after 2017-02-19c Fix from $1,6002017-08-21 MEDIUM 6.1 CVE-2017-12583 DokuWiki through 2017-02-19b has XSS in the at parameter (aka the DATE_AT variable) to doku.php. Dokuwiki after 2017-02-19b Fix from $1,6002017-08-06 MEDIUM 6.5 CVE-2016-7965 DokuWiki 2016-06-26a and older uses $_SERVER[HTTP_HOST] instead of the baseurl setting as part of the password-reset URL. This can lead to phishing a… Dokuwiki after 2016-06-26a Fix from $1,6002016-10-31 HIGH 8.6 CVE-2016-7964 The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php in DokuWiki 2016-06-26a and older, when media file fetching is enabled, has no… Dokuwiki Patch available Fix from $1,9502016-10-31 MEDIUM 6.5 CVE-2015-2172 DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users t… Dokuwiki 2014-05-05d / 2014-09-29c+ Fix from $1,6002015-03-30 MEDIUM 5.0 CVE-2014-8761 inc/template.php in DokuWiki before 2014-05-05a only checks for access to the root namespace, which allows remote attackers to access arbitrary image… Dokuwiki after 2013-12-08 Fix from $1,6002014-10-22 MEDIUM 5.0 CVE-2014-8762 The ajax_mediadiff function in DokuWiki before 2014-05-05a allows remote attackers to access arbitrary images via a crafted namespace in the ns param… Dokuwiki after 2013-12-08 Fix from $1,6002014-10-22 MEDIUM 5.0 CVE-2014-8763 DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password sta… Dokuwiki after 2014-05-05a Fix from $1,6002014-10-22 MEDIUM 5.0 CVE-2011-3727 DokuWiki 2009-12-25c allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path… Dokuwiki No fix yet Fix from $1,6002011-09-23 HIGH 7.5 CVE-2010-0288EPSS 11% A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers … Dokuwiki No fix yet Fix from $1,9502010-02-15 MEDIUM 6.8 CVE-2010-0289 Multiple cross-site request forgery (CSRF) vulnerabilities in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25c allow remo… Dokuwiki Mitigation only Fix from $1,6002010-02-15 MEDIUM 5.0 CVE-2010-0287EPSS 11% Directory traversal vulnerability in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to list the… Dokuwiki No fix yet Fix from $1,6002010-02-15 HIGH 9.3 CVE-2009-1960EPSS 23% inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute… Dokuwiki Patch available Fix from $1,9502009-06-08