Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ikiwiki MEDIUM 6.1
CVE-2010-1673

A cross-site scripting (XSS) vulnerability in ikiwiki before 3.20101112 allows remote attackers to inject arbitrary web script or HTML via a comment.

Fix: 3.20101112+
Fix from $1,600 2019-10-30
Ikiwiki MEDIUM 6.1
CVE-2011-0428

Cross Site Scripting (XSS) in ikiwiki before 3.20110122 could allow remote attackers to insert arbitrary JavaScript due to insufficient checking in c…

Fix: 3.20110122+
Fix from $1,600 2019-10-29
Ikiwiki HIGH 7.5
CVE-2019-9187

ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact also includes reading local fi…

Fix: 3.20170111.1 / 3.20190226+
Fix from $1,950 2019-06-05
Ikiwiki MEDIUM 6.5
CVE-2016-9645

The fix for ikiwiki for CVE-2016-10026 was incomplete resulting in editing restriction bypass for git revert when using git versions older than 2.8.0…

Fix: 2.8+
Fix from $1,600 2018-04-10
Ikiwiki HIGH 7.5
CVE-2016-10026

ikiwiki 3.20161219 does not properly check if a revision changes the access permissions for a page on sites with the git and recentchanges plugins an…

Mitigation only
Fix from $1,950 2017-02-13
Ikiwiki MEDIUM 5.0
CVE-2009-2944

Incomplete blacklist vulnerability in the teximg plugin in ikiwiki before 3.1415926 and 2.x before 2.53.4 allows context-dependent attackers to read …

Fix: after 3.141592
Fix from $1,600 2009-08-31
Ikiwiki MEDIUM 6.8
CVE-2008-0169

Plugin/passwordauth.pm (aka the passwordauth plugin) in ikiwiki 1.34 through 2.47 allows remote attackers to bypass authentication, and login to any …

Mitigation only
Fix from $1,600 2008-06-03