moinmoin records
18 published records for vendor moinmoin.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2004-1463No exploit | Unknown vulnerability in the PageEditor in MoinMoin 1.2.2 and earlier, related to Access Control Lists (ACL), has unknown impact.moinmoin · moinmoin | Critical10.0 | — | 2.3% | Dec 31, 2004 |
31Monitor | CVE-2004-0708No exploit | MoinMoin 1.2.1 and earlier allows remote attackers to gain privileges by creating a user with the same name as an existing group that has himoinmoin · moinmoin | High7.5 | — | 1.8% | Jul 27, 2004 |
30Monitor | CVE-2004-1462No exploit | Unknown vulnerability in MoinMoin 1.2.2 and earlier allows remote attackers to gain unauthorized access to administrator functions such as (moinmoin · moinmoin | High7.5 | — | 1.6% | Dec 31, 2004 |
28Monitor | CVE-2008-1937No exploit | The user form processing (userform.py) in MoinMoin before 1.6.3, when using ACLs or a non-empty superusers list, does not properly manage usmoinmoin · moinmoin · CWE-264 | Medium6.8 | — | 1.7% | Apr 25, 2008 |
24Monitor | CVE-2008-0782Proof of concept | Directory traversal vulnerability in MoinMoin 1.5.8 and earlier allows remote attackers to overwrite arbitrary files via a ..moinmoin · moinmoin · CWE-22 | Medium5.0 | — | 14.9% | Feb 14, 2008 |
24Monitor | CVE-2007-2423Proof of concept | Cross-site scripting (XSS) vulnerability in index.php in MoinMoin 1.5.7 allows remote attackers to inject arbitrary web script or HTML via tmoinmoin · moinmoin | Medium5.8 | — | 3.6% | May 1, 2007 |
21Monitor | CVE-2008-1099No exploit | _macro_Getval in wikimacro.py in MoinMoin 1.5.8 and earlier does not properly enforce ACLs, which allows remote attackers to read protected moinmoin · moinmoin · CWE-264 | Medium5.0 | — | 2.0% | Mar 5, 2008 |
20Monitor | CVE-2007-2637No exploit | MoinMoin before 20070507 does not properly enforce ACLs for calendars and includes, which allows remote attackers to read certain pages via moinmoin · moinmoin | Medium5.0 | — | 1.5% | May 13, 2007 |
20Monitor | CVE-2007-0902No exploit | Unspecified vulnerability in the "Show debugging information" feature in MoinMoin 1.5.7 allows remote attackers to obtain sensitive informatmoinmoin · moinmoin | Medium5.0 | — | 1.4% | Feb 13, 2007 |
19Monitor | CVE-2009-0260Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin before 1.8.1 allow remote attackers to inject arbitrmoinmoin · moinmoin · CWE-79 | Medium4.3 | — | 5.5% | Jan 23, 2009 |
18Monitor | CVE-2008-0781No exploit | Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.5.8 and earlier allow remote attackers to inject amoinmoin · moinmoin · CWE-79 | Medium4.3 | — | 2.6% | Feb 14, 2008 |
18Monitor | CVE-2009-1482No exploit | Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote attackers to inject amoinmo · moinmoin · CWE-79 | Medium4.3 | — | 2.5% | Apr 29, 2009 |
18Monitor | CVE-2007-0857No exploit | Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin before 1.5.7 allow remote attackers to inject arbitrary web script or HTML vmoinmoin · moinmoin | Medium4.3 | — | 2.4% | Feb 8, 2007 |
18Monitor | CVE-2009-0312No exploit | Cross-site scripting (XSS) vulnerability in the antispam feature (security/antispam.py) in MoinMoin 1.7 and 1.8.1 allows remote attackers tomoinmoin · moinmoin · CWE-79 | Medium4.3 | — | 2.4% | Jan 27, 2009 |
18Monitor | CVE-2008-3381No exploit | Multiple cross-site scripting (XSS) vulnerabilities in macro/AdvancedSearch.py in moin (and MoinMoin) 1.6.3 and 1.7.0 allow remote attackersmoinmoin · moinmoin · CWE-79 | Medium4.3 | — | 2.1% | Jul 30, 2008 |
18Monitor | CVE-2008-1098No exploit | Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.5.8 and earlier allow remote attackers to inject arbitrary web script or Hmoinmoin · moinmoin · CWE-79 | Medium4.3 | — | 1.8% | Mar 5, 2008 |
18Monitor | CVE-2007-0901No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Info pages in MoinMoin 1.5.7 allow remote attackers to inject arbitrary web script ormoinmoin · moinmoin | Medium4.3 | — | 1.8% | Feb 13, 2007 |
18Monitor | CVE-2008-0780No exploit | Cross-site scripting (XSS) vulnerability in MoinMoin 1.5.x through 1.5.8 and 1.6.x before 1.6.1 allows remote attackers to inject arbitrary moinmoin · moinmoin · CWE-79 | Medium4.3 | — | 1.8% | Feb 14, 2008 |
- CVE-2004-146341Plan
Unknown vulnerability in the PageEditor in MoinMoin 1.2.2 and earlier, related to Access Control Lists (ACL), has unknown impact.
CriticalCVSS 10.0No exploitEPSS 2%moinmoin · moinmoinDec 31, 2004
- CVE-2004-070831Monitor
MoinMoin 1.2.1 and earlier allows remote attackers to gain privileges by creating a user with the same name as an existing group that has hi
HighCVSS 7.5No exploitEPSS 2%moinmoin · moinmoinJul 27, 2004
- CVE-2004-146230Monitor
Unknown vulnerability in MoinMoin 1.2.2 and earlier allows remote attackers to gain unauthorized access to administrator functions such as (
HighCVSS 7.5No exploitEPSS 2%moinmoin · moinmoinDec 31, 2004
- CVE-2008-193728Monitor
The user form processing (userform.py) in MoinMoin before 1.6.3, when using ACLs or a non-empty superusers list, does not properly manage us
MediumCVSS 6.8No exploitEPSS 2%moinmoin · moinmoinApr 25, 2008
- CVE-2008-078224Monitor
Directory traversal vulnerability in MoinMoin 1.5.8 and earlier allows remote attackers to overwrite arbitrary files via a ..
MediumCVSS 5.0Proof of conceptEPSS 15%moinmoin · moinmoinFeb 14, 2008
- CVE-2007-242324Monitor
Cross-site scripting (XSS) vulnerability in index.php in MoinMoin 1.5.7 allows remote attackers to inject arbitrary web script or HTML via t
MediumCVSS 5.8Proof of conceptEPSS 4%moinmoin · moinmoinMay 1, 2007
- CVE-2008-109921Monitor
_macro_Getval in wikimacro.py in MoinMoin 1.5.8 and earlier does not properly enforce ACLs, which allows remote attackers to read protected
MediumCVSS 5.0No exploitEPSS 2%moinmoin · moinmoinMar 5, 2008
- CVE-2007-263720Monitor
MoinMoin before 20070507 does not properly enforce ACLs for calendars and includes, which allows remote attackers to read certain pages via
MediumCVSS 5.0No exploitEPSS 1%moinmoin · moinmoinMay 13, 2007
- CVE-2007-090220Monitor
Unspecified vulnerability in the "Show debugging information" feature in MoinMoin 1.5.7 allows remote attackers to obtain sensitive informat
MediumCVSS 5.0No exploitEPSS 1%moinmoin · moinmoinFeb 13, 2007
- CVE-2009-026019Monitor
Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin before 1.8.1 allow remote attackers to inject arbitr
MediumCVSS 4.3Proof of conceptEPSS 5%moinmoin · moinmoinJan 23, 2009
- CVE-2008-078118Monitor
Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.5.8 and earlier allow remote attackers to inject a
MediumCVSS 4.3No exploitEPSS 3%moinmoin · moinmoinFeb 14, 2008
- CVE-2009-148218Monitor
Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote attackers to inject a
MediumCVSS 4.3No exploitEPSS 3%moinmo · moinmoinApr 29, 2009
- CVE-2007-085718Monitor
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin before 1.5.7 allow remote attackers to inject arbitrary web script or HTML v
MediumCVSS 4.3No exploitEPSS 2%moinmoin · moinmoinFeb 8, 2007
- CVE-2009-031218Monitor
Cross-site scripting (XSS) vulnerability in the antispam feature (security/antispam.py) in MoinMoin 1.7 and 1.8.1 allows remote attackers to
MediumCVSS 4.3No exploitEPSS 2%moinmoin · moinmoinJan 27, 2009
- CVE-2008-338118Monitor
Multiple cross-site scripting (XSS) vulnerabilities in macro/AdvancedSearch.py in moin (and MoinMoin) 1.6.3 and 1.7.0 allow remote attackers
MediumCVSS 4.3No exploitEPSS 2%moinmoin · moinmoinJul 30, 2008
- CVE-2008-109818Monitor
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.5.8 and earlier allow remote attackers to inject arbitrary web script or H
MediumCVSS 4.3No exploitEPSS 2%moinmoin · moinmoinMar 5, 2008
- CVE-2007-090118Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Info pages in MoinMoin 1.5.7 allow remote attackers to inject arbitrary web script or
MediumCVSS 4.3No exploitEPSS 2%moinmoin · moinmoinFeb 13, 2007
- CVE-2008-078018Monitor
Cross-site scripting (XSS) vulnerability in MoinMoin 1.5.x through 1.5.8 and 1.6.x before 1.6.1 allows remote attackers to inject arbitrary
MediumCVSS 4.3No exploitEPSS 2%moinmoin · moinmoinFeb 14, 2008