Skip to content
Noroxi

pmwiki records

8 published records for vendor pmwiki.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 12.5%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 20

Bar: total · dark part: CISA KEV.

Attack profile

All records

8 records
  • The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitrary code via PHP sequ

    HighCVSS 7.5WeaponizedEPSS 52%

    pmwiki · pmwikiDec 22, 2011

  • CVE-2006-2840
    27Monitor

    Cross-site scripting (XSS) vulnerability in (1) uploads.php and (2) "url links" in PmWiki 2.1.6 and earlier allows remote attackers to injec

    MediumCVSS 6.8No exploitEPSS 1%

    pmwiki · pmwikiJun 6, 2006

  • CVE-2010-4662
    24Monitor

    PmWiki before 2.2.21 has XSS.

    MediumCVSS 6.1No exploitEPSS 1%

    pmwiki · pmwikiFeb 5, 2020

  • CVE-2006-0479
    18Monitor

    pmwiki.php in PmWiki 2.1 beta 20, with register_globals enabled, allows remote attackers to bypass protection mechanisms that deregister glo

    MediumCVSS 4.3Proof of conceptEPSS 3%

    pmwiki · pmwikiJan 31, 2006

  • CVE-2005-3849
    18Monitor

    Cross-site scripting (XSS) vulnerability in the Search module in PmWiki up to 2.0.12 allows remote attackers to inject arbitrary web script

    MediumCVSS 4.3Proof of conceptEPSS 2%

    pmwiki · pmwikiNov 26, 2005

  • CVE-2010-4748
    17Monitor

    Cross-site scripting (XSS) vulnerability in pmwiki.php in PmWiki 2.2.20 allows remote attackers to inject arbitrary web script or HTML via t

    MediumCVSS 4.3No exploitEPSS 1%

    pmwiki · pmwikiMar 1, 2011

  • CVE-2006-4453
    17Monitor

    Cross-site scripting (XSS) vulnerability in PmWiki before 2.1.18 allows remote attackers to inject arbitrary web script or HTML via unspecif

    MediumCVSS 4.3No exploitEPSS 1%

    pmwiki · pmwikiAug 30, 2006

  • CVE-2010-1481
    14Monitor

    Cross-site scripting (XSS) vulnerability in the table feature in PmWiki 2.2.15 allows remote authenticated users to inject arbitrary web scr

    LowCVSS 3.5No exploitEPSS 1%

    pmwiki · pmwikiMay 12, 2010