Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2010-1673 A cross-site scripting (XSS) vulnerability in ikiwiki before 3.20101112 allows remote attackers to inject arbitrary web script or HTML via a comment. Ikiwiki 3.20101112+ Fix from $1,6002019-10-30 MEDIUM 6.1 CVE-2011-0428 Cross Site Scripting (XSS) in ikiwiki before 3.20110122 could allow remote attackers to insert arbitrary JavaScript due to insufficient checking in c… Ikiwiki 3.20110122+ Fix from $1,6002019-10-29 HIGH 7.5 CVE-2019-9187 ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact also includes reading local fi… Ikiwiki 3.20170111.1 / 3.20190226+ Fix from $1,9502019-06-05 MEDIUM 6.5 CVE-2016-9645 The fix for ikiwiki for CVE-2016-10026 was incomplete resulting in editing restriction bypass for git revert when using git versions older than 2.8.0… Ikiwiki 2.8+ Fix from $1,6002018-04-10 HIGH 7.5 CVE-2016-10026 ikiwiki 3.20161219 does not properly check if a revision changes the access permissions for a page on sites with the git and recentchanges plugins an… Ikiwiki Mitigation only Fix from $1,9502017-02-13 MEDIUM 5.0 CVE-2009-2944 Incomplete blacklist vulnerability in the teximg plugin in ikiwiki before 3.1415926 and 2.x before 2.53.4 allows context-dependent attackers to read … Ikiwiki after 3.141592 Fix from $1,6002009-08-31 MEDIUM 6.8 CVE-2008-0169 Plugin/passwordauth.pm (aka the passwordauth plugin) in ikiwiki 1.34 through 2.47 allows remote attackers to bypass authentication, and login to any … Ikiwiki Mitigation only Fix from $1,6002008-06-03