Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dokuwiki MEDIUM 5.3
CVE-2019-25338

DokuWiki 2018-04-22b contains a username enumeration vulnerability in its password reset functionality that allows attackers to identify valid user a…

No fix yet
Fix from $1,600 2026-02-12
Dokuwiki MEDIUM 5.4
CVE-2023-34408

DokuWiki before 2023-04-04a allows XSS via RSS titles.

Fix: 2023-04-04a+
Fix from $1,600 2023-06-05
Dokuwiki CRITICAL 9.6
CVE-2018-15474

CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remot…

Fix: after 2018-04-22a
Fix from $2,300 2018-09-07
Dokuwiki MEDIUM 6.1
CVE-2017-12979

DokuWiki through 2017-02-19c has stored XSS when rendering a malicious language name in a code element, in /inc/parser/xhtml.php. An attacker can cre…

Fix: after 2017-02-19c
Fix from $1,600 2017-08-21
Dokuwiki MEDIUM 6.1
CVE-2017-12980

DokuWiki through 2017-02-19c has stored XSS when rendering a malicious RSS or Atom feed, in /inc/parser/xhtml.php. An attacker can create or edit a w…

Fix: after 2017-02-19c
Fix from $1,600 2017-08-21
Dokuwiki MEDIUM 6.1
CVE-2017-12583

DokuWiki through 2017-02-19b has XSS in the at parameter (aka the DATE_AT variable) to doku.php.

Fix: after 2017-02-19b
Fix from $1,600 2017-08-06
Dokuwiki MEDIUM 6.5
CVE-2016-7965

DokuWiki 2016-06-26a and older uses $_SERVER[HTTP_HOST] instead of the baseurl setting as part of the password-reset URL. This can lead to phishing a…

Fix: after 2016-06-26a
Fix from $1,600 2016-10-31
Dokuwiki HIGH 8.6
CVE-2016-7964

The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php in DokuWiki 2016-06-26a and older, when media file fetching is enabled, has no…

Patch available
Fix from $1,950 2016-10-31
Dokuwiki MEDIUM 6.5
CVE-2015-2172

DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users t…

Fix: 2014-05-05d / 2014-09-29c+
Fix from $1,600 2015-03-30
Dokuwiki MEDIUM 5.0
CVE-2014-8761

inc/template.php in DokuWiki before 2014-05-05a only checks for access to the root namespace, which allows remote attackers to access arbitrary image…

Fix: after 2013-12-08
Fix from $1,600 2014-10-22
Dokuwiki MEDIUM 5.0
CVE-2014-8762

The ajax_mediadiff function in DokuWiki before 2014-05-05a allows remote attackers to access arbitrary images via a crafted namespace in the ns param…

Fix: after 2013-12-08
Fix from $1,600 2014-10-22
Dokuwiki MEDIUM 5.0
CVE-2014-8763

DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password sta…

Fix: after 2014-05-05a
Fix from $1,600 2014-10-22
Dokuwiki MEDIUM 5.0
CVE-2011-3727

DokuWiki 2009-12-25c allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path…

No fix yet
Fix from $1,600 2011-09-23
Dokuwiki HIGH 7.5
CVE-2010-0288EPSS 11%

A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers …

No fix yet
Fix from $1,950 2010-02-15
Dokuwiki MEDIUM 6.8
CVE-2010-0289

Multiple cross-site request forgery (CSRF) vulnerabilities in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25c allow remo…

Mitigation only
Fix from $1,600 2010-02-15
Dokuwiki MEDIUM 5.0
CVE-2010-0287EPSS 11%

Directory traversal vulnerability in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to list the…

No fix yet
Fix from $1,600 2010-02-15
Dokuwiki HIGH 9.3
CVE-2009-1960EPSS 23%

inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute…

Patch available
Fix from $1,950 2009-06-08