Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2019-25338
DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user a…
Dokuwiki
No fix yet
MEDIUM 5.4
CVE-2023-34408
DokuWiki before 2023-04-04a allows XSS via RSS titles.
Dokuwiki
2023-04-04a+
CRITICAL 9.6
CVE-2018-15474
CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remot…
Dokuwiki
after 2018-04-22a
MEDIUM 6.1
CVE-2017-12979
DokuWiki through 2017-02-19c has stored XSS when rendering a malicious language name in a code element, in /inc/parser/xhtml.php. An attacker can cre…
Dokuwiki
after 2017-02-19c
MEDIUM 6.1
CVE-2017-12980
DokuWiki through 2017-02-19c has stored XSS when rendering a malicious RSS or Atom feed, in /inc/parser/xhtml.php. An attacker can create or edit a w…
Dokuwiki
after 2017-02-19c
MEDIUM 6.1
CVE-2017-12583
DokuWiki through 2017-02-19b has XSS in the at parameter (aka the DATE_AT variable) to doku.php.
Dokuwiki
after 2017-02-19b
MEDIUM 6.5
CVE-2016-7965
DokuWiki 2016-06-26a and older uses $_SERVER[HTTP_HOST] instead of the baseurl setting as part of the password-reset URL. This can lead to phishing a…
Dokuwiki
after 2016-06-26a
HIGH 8.6
CVE-2016-7964
The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php in DokuWiki 2016-06-26a and older, when media file fetching is enabled, has no…
Dokuwiki
Patch available
MEDIUM 6.5
CVE-2015-2172
DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users t…
Dokuwiki
2014-05-05d / 2014-09-29c+
MEDIUM 5.0
CVE-2014-8761
inc/template.php in DokuWiki before 2014-05-05a only checks for access to the root namespace, which allows remote attackers to access arbitrary image…
Dokuwiki
after 2013-12-08
MEDIUM 5.0
CVE-2014-8762
The ajax_mediadiff function in DokuWiki before 2014-05-05a allows remote attackers to access arbitrary images via a crafted namespace in the ns param…
Dokuwiki
after 2013-12-08
MEDIUM 5.0
CVE-2014-8763
DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password sta…
Dokuwiki
after 2014-05-05a
MEDIUM 5.0
CVE-2011-3727
DokuWiki 2009-12-25c allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path…
Dokuwiki
No fix yet
HIGH 7.5
CVE-2010-0288EPSS 11%
A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers …
Dokuwiki
No fix yet
MEDIUM 6.8
CVE-2010-0289
Multiple cross-site request forgery (CSRF) vulnerabilities in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25c allow remo…
Dokuwiki
Mitigation only
MEDIUM 5.0
CVE-2010-0287EPSS 11%
Directory traversal vulnerability in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to list the…
Dokuwiki
No fix yet
HIGH 9.3
CVE-2009-1960EPSS 23%
inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute…
Dokuwiki
Patch available