pmwiki records
8 published records for vendor pmwiki.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 12.5%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2011-4453Weaponized | The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitrary code via PHP sequpmwiki · pmwiki · CWE-94 | High7.5 | — | 52.0% | Dec 22, 2011 |
27Monitor | CVE-2006-2840No exploit | Cross-site scripting (XSS) vulnerability in (1) uploads.php and (2) "url links" in PmWiki 2.1.6 and earlier allows remote attackers to injecpmwiki · pmwiki | Medium6.8 | — | 1.3% | Jun 6, 2006 |
24Monitor | CVE-2010-4662No exploit | PmWiki before 2.2.21 has XSS.pmwiki · pmwiki · CWE-79 | Medium6.1 | — | 0.8% | Feb 5, 2020 |
18Monitor | CVE-2006-0479Proof of concept | pmwiki.php in PmWiki 2.1 beta 20, with register_globals enabled, allows remote attackers to bypass protection mechanisms that deregister glopmwiki · pmwiki | Medium4.3 | — | 3.1% | Jan 31, 2006 |
18Monitor | CVE-2005-3849Proof of concept | Cross-site scripting (XSS) vulnerability in the Search module in PmWiki up to 2.0.12 allows remote attackers to inject arbitrary web script pmwiki · pmwiki | Medium4.3 | — | 2.0% | Nov 26, 2005 |
17Monitor | CVE-2010-4748No exploit | Cross-site scripting (XSS) vulnerability in pmwiki.php in PmWiki 2.2.20 allows remote attackers to inject arbitrary web script or HTML via tpmwiki · pmwiki · CWE-79 | Medium4.3 | — | 1.3% | Mar 1, 2011 |
17Monitor | CVE-2006-4453No exploit | Cross-site scripting (XSS) vulnerability in PmWiki before 2.1.18 allows remote attackers to inject arbitrary web script or HTML via unspecifpmwiki · pmwiki | Medium4.3 | — | 1.2% | Aug 30, 2006 |
14Monitor | CVE-2010-1481No exploit | Cross-site scripting (XSS) vulnerability in the table feature in PmWiki 2.2.15 allows remote authenticated users to inject arbitrary web scrpmwiki · pmwiki · CWE-79 | Low3.5 | — | 0.9% | May 12, 2010 |
- CVE-2011-445346Plan
The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitrary code via PHP sequ
HighCVSS 7.5WeaponizedEPSS 52%pmwiki · pmwikiDec 22, 2011
- CVE-2006-284027Monitor
Cross-site scripting (XSS) vulnerability in (1) uploads.php and (2) "url links" in PmWiki 2.1.6 and earlier allows remote attackers to injec
MediumCVSS 6.8No exploitEPSS 1%pmwiki · pmwikiJun 6, 2006
- CVE-2010-466224Monitor
PmWiki before 2.2.21 has XSS.
MediumCVSS 6.1No exploitEPSS 1%pmwiki · pmwikiFeb 5, 2020
- CVE-2006-047918Monitor
pmwiki.php in PmWiki 2.1 beta 20, with register_globals enabled, allows remote attackers to bypass protection mechanisms that deregister glo
MediumCVSS 4.3Proof of conceptEPSS 3%pmwiki · pmwikiJan 31, 2006
- CVE-2005-384918Monitor
Cross-site scripting (XSS) vulnerability in the Search module in PmWiki up to 2.0.12 allows remote attackers to inject arbitrary web script
MediumCVSS 4.3Proof of conceptEPSS 2%pmwiki · pmwikiNov 26, 2005
- CVE-2010-474817Monitor
Cross-site scripting (XSS) vulnerability in pmwiki.php in PmWiki 2.2.20 allows remote attackers to inject arbitrary web script or HTML via t
MediumCVSS 4.3No exploitEPSS 1%pmwiki · pmwikiMar 1, 2011
- CVE-2006-445317Monitor
Cross-site scripting (XSS) vulnerability in PmWiki before 2.1.18 allows remote attackers to inject arbitrary web script or HTML via unspecif
MediumCVSS 4.3No exploitEPSS 1%pmwiki · pmwikiAug 30, 2006
- CVE-2010-148114Monitor
Cross-site scripting (XSS) vulnerability in the table feature in PmWiki 2.2.15 allows remote authenticated users to inject arbitrary web scr
LowCVSS 3.5No exploitEPSS 1%pmwiki · pmwikiMay 12, 2010