Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Moinmoin MEDIUM 5.4
CVE-2020-15275

MoinMoin is a wiki engine. In MoinMoin before version 1.9.11, an attacker with write permissions can upload an SVG file that contains malicious javas…

Fix: 1.9.11+
Fix from $1,600 2020-11-11
Moinmoin MEDIUM 6.1
CVE-2016-7148

MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross Site Scri…

No fix yet
Fix from $1,600 2016-11-10
Moinmoin MEDIUM 6.1
CVE-2016-7146

MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation or crafted URL" approach, related to a "…

No fix yet
Fix from $1,600 2016-11-10
Moinmoin MEDIUM 6.4
CVE-2012-6080

Directory traversal vulnerability in the _do_attachment_move function in the AttachFile action (action/AttachFile.py) in MoinMoin 1.9.3 through 1.9.5…

Patch available
Fix from $1,600 2013-01-03
Moinmoin MEDIUM 6.0
CVE-2012-6081EPSS 31%

Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in M…

Fix: after 1.9.5
Fix from $1,600 2013-01-03
Moinmoin MEDIUM 6.0
CVE-2012-6495EPSS 19%

Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMo…

Fix: after 1.9.5
Fix from $1,600 2013-01-03
Moinmoin MEDIUM 6.0
CVE-2012-4404

security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "…

Mitigation only
Fix from $1,600 2012-09-10
Moinmoin MEDIUM 5.0
CVE-2010-1238

MoinMoin 1.7.1 allows remote attackers to bypass the textcha protection mechanism by modifying the textcha-question and textcha-answer fields to have…

Mitigation only
Fix from $1,600 2010-04-05
Moinmoin HIGH 7.5
CVE-2009-4762

MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchical ACLs, …

Patch available
Fix from $1,950 2010-03-29
Moinmoin HIGH 7.5
CVE-2010-0669

MoinMoin before 1.8.7 and 1.9.x before 1.9.2 does not properly sanitize user profiles, which has unspecified impact and attack vectors.

Fix: after 1.8.6
Fix from $1,950 2010-02-26
Moinmoin HIGH 7.5
CVE-2010-0717

The default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does not prevent unsafe package actions, which has unspecifie…

Fix: after 1.8.6
Fix from $1,950 2010-02-26
Moinmoin MEDIUM 6.8
CVE-2010-0668

Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors, related …

Patch available
Fix from $1,600 2010-02-26
Moinmoin MEDIUM 5.0
CVE-2010-0667

MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable…

Mitigation only
Fix from $1,600 2010-02-26
Moinmoin MEDIUM 6.8
CVE-2008-6603

MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote attackers to bypass intended…

No fix yet
Fix from $1,600 2009-04-03
Moinmoin MEDIUM 5.0
CVE-2008-6548

The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include…

Mitigation only
Fix from $1,600 2009-03-30
Moinmoin MEDIUM 5.0
CVE-2008-6549

The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are not thread-…

No fix yet
Fix from $1,600 2009-03-30