twiki records
30 published records for vendor twiki.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 3 · 10%
- Pre-auth RCE
- 11
- With a fix record
- 3.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-189 Numeric Errors1
The weakness classes this vendor ships most often: where to look.
CWEAll records
30 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
59Plan | CVE-2004-1037Weaponized | The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.twiki · twiki | Critical10.0 | — | 61.7% | Mar 1, 2005 |
53Plan | CVE-2014-7236Weaponized | Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the detwiki · twiki · CWE-74 | Critical9.1 | — | 55.6% | Feb 17, 2020 |
51Plan | CVE-2005-2877Weaponized | The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metachatwiki · twiki | High7.5 | — | 70.9% | Sep 16, 2005 |
41Plan | CVE-2008-5305Proof of concept | Eval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable.twiki · twiki · CWE-94 | Critical10.0 | — | 4.6% | Dec 9, 2008 |
40Plan | CVE-2013-1751No exploit | TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containintwiki · twiki · CWE-20 | Critical9.8 | — | 4.9% | Nov 7, 2019 |
40Plan | CVE-2005-3056No exploit | TWiki allows arbitrary shell command execution via the Include functiontwiki · twiki · CWE-74 | Critical9.8 | — | 3.5% | Nov 1, 2019 |
37Monitor | CVE-2006-6071No exploit | TWiki 4.0.5 and earlier, when running under Apache 1.3 using ApacheLogin with sessions and "ErrorDocument 401" redirects to a valid wiki toptwiki · twiki | Critical9.0 | — | 2.2% | Dec 1, 2006 |
33Monitor | CVE-2014-7237No exploit | lib/TWiki/Sandbox.pm in TWiki 6.0.0 and earlier, when running on Windows, allows remote attackers to bypass intended access restrictions andtwiki · twiki · CWE-264 | Medium6.8 | — | 20.1% | Oct 15, 2014 |
31Monitor | CVE-2012-6330Proof of concept | The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to ctwiki · twiki · CWE-189 | Medium5.0 | — | 35.7% | Jan 4, 2013 |
31Monitor | CVE-2006-3819Proof of concept | Eval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arbitrary Perl code viatwiki · twiki | High7.5 | — | 4.1% | Jul 26, 2006 |
31Monitor | CVE-2005-0516No exploit | The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that genetwiki · imagegalleryplugin | High7.5 | — | 2.3% | Feb 23, 2005 |
31Monitor | CVE-2006-1386No exploit | The (1) rdiff and (2) preview scripts in TWiki 4.0 and 4.0.1 ignore access control settings, which allows remote attackers to read restrictetwiki · twiki | High7.5 | — | 1.8% | Mar 26, 2006 |
29Monitor | CVE-2008-3195Proof of concept | Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows rtwiki · twiki · CWE-22 | Medium6.8 | — | 8.3% | Sep 18, 2008 |
27Monitor | CVE-2009-4898No exploit | Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.2 allows remote attackers to hijack the authentication of arbitrary usertwiki · twiki · CWE-352 | Medium6.8 | — | 0.6% | Sep 7, 2010 |
27Monitor | CVE-2008-4998No exploit | postinst in twiki 4.1.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/twiki temporary file.twiki · twiki · CWE-59 | Medium6.9 | — | 0.3% | Nov 7, 2008 |
24Monitor | CVE-2018-20212No exploit | bin/statistics in TWiki 6.0.2 allows cross-site scripting (XSS) via the webs parameter.twiki · twiki · CWE-79 | Medium6.1 | — | 1.6% | Mar 21, 2019 |
24Monitor | CVE-2009-1339No exploit | Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.1 allows remote authenticated users to hijack the authentication of arbitwiki · twiki · CWE-352 | Medium6.0 | — | 0.7% | Apr 30, 2009 |
21Monitor | CVE-2006-4294Proof of concept | Directory traversal vulnerability in viewfile in TWiki 4.0.0 through 4.0.4 allows remote attackers to read arbitrary files via a ..twiki · twiki | Medium5.0 | — | 3.9% | Sep 8, 2006 |
20Monitor | CVE-2007-5193No exploit | The default configuration for twiki 4.1.2 on Debian GNU/Linux, and possibly other operating systems, specifies the work area directory (cfg{debian · debian linux | Medium5.0 | — | 1.6% | Oct 4, 2007 |
20Monitor | CVE-2006-2942No exploit | TWiki 4.0.0, 4.0.1, and 4.0.2 allows remote attackers to gain Twiki administrator privileges via a TWiki.TWikiRegistration form with a modiftwiki · twiki | Medium5.1 | — | 1.6% | Jun 20, 2006 |
19Monitor | CVE-2011-3010Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via twiki · twiki · CWE-79 | Medium4.3 | — | 5.5% | Sep 30, 2011 |
18Monitor | CVE-2010-3841Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inject arbitrary web scrtwiki · twiki · CWE-79 | Medium4.3 | — | 3.1% | Oct 18, 2010 |
18Monitor | CVE-2011-1838Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in TemplateLogin.pm in TWiki before 5.0.2 allow remote attackers to inject arbitrary webtwiki · twiki · CWE-79 | Medium4.3 | — | 2.7% | May 20, 2011 |
18Monitor | CVE-2008-5304Proof of concept | Cross-site scripting (XSS) vulnerability in TWiki before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via the %URLPAtwiki · twiki · CWE-79 | Medium4.3 | — | 2.2% | Dec 9, 2008 |
18Monitor | CVE-2012-0979No exploit | Cross-site scripting (XSS) vulnerability in TWiki allows remote attackers to inject arbitrary web script or HTML via the organization field twiki · twiki · CWE-79 | Medium4.3 | — | 2.0% | Feb 2, 2012 |
- CVE-2004-103759Plan
The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.
CriticalCVSS 10.0WeaponizedEPSS 62%twiki · twikiMar 1, 2005
- CVE-2014-723653Plan
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the de
CriticalCVSS 9.1WeaponizedEPSS 56%twiki · twikiFeb 17, 2020
- CVE-2005-287751Plan
The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metacha
HighCVSS 7.5WeaponizedEPSS 71%twiki · twikiSep 16, 2005
- CVE-2008-530541Plan
Eval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable.
CriticalCVSS 10.0Proof of conceptEPSS 5%twiki · twikiDec 9, 2008
- CVE-2013-175140Plan
TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containin
CriticalCVSS 9.8No exploitEPSS 5%twiki · twikiNov 7, 2019
- CVE-2005-305640Plan
TWiki allows arbitrary shell command execution via the Include function
CriticalCVSS 9.8No exploitEPSS 3%twiki · twikiNov 1, 2019
- CVE-2006-607137Monitor
TWiki 4.0.5 and earlier, when running under Apache 1.3 using ApacheLogin with sessions and "ErrorDocument 401" redirects to a valid wiki top
CriticalCVSS 9.0No exploitEPSS 2%twiki · twikiDec 1, 2006
- CVE-2014-723733Monitor
lib/TWiki/Sandbox.pm in TWiki 6.0.0 and earlier, when running on Windows, allows remote attackers to bypass intended access restrictions and
MediumCVSS 6.8No exploitEPSS 20%twiki · twikiOct 15, 2014
- CVE-2012-633031Monitor
The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to c
MediumCVSS 5.0Proof of conceptEPSS 36%twiki · twikiJan 4, 2013
- CVE-2006-381931Monitor
Eval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arbitrary Perl code via
HighCVSS 7.5Proof of conceptEPSS 4%twiki · twikiJul 26, 2006
- CVE-2005-051631Monitor
The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that gene
HighCVSS 7.5No exploitEPSS 2%twiki · imagegallerypluginFeb 23, 2005
- CVE-2006-138631Monitor
The (1) rdiff and (2) preview scripts in TWiki 4.0 and 4.0.1 ignore access control settings, which allows remote attackers to read restricte
HighCVSS 7.5No exploitEPSS 2%twiki · twikiMar 26, 2006
- CVE-2008-319529Monitor
Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows r
MediumCVSS 6.8Proof of conceptEPSS 8%twiki · twikiSep 18, 2008
- CVE-2009-489827Monitor
Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.2 allows remote attackers to hijack the authentication of arbitrary user
MediumCVSS 6.8No exploitEPSS 1%twiki · twikiSep 7, 2010
- CVE-2008-499827Monitor
postinst in twiki 4.1.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/twiki temporary file.
MediumCVSS 6.9No exploitEPSS 0%twiki · twikiNov 7, 2008
- CVE-2018-2021224Monitor
bin/statistics in TWiki 6.0.2 allows cross-site scripting (XSS) via the webs parameter.
MediumCVSS 6.1No exploitEPSS 2%twiki · twikiMar 21, 2019
- CVE-2009-133924Monitor
Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.1 allows remote authenticated users to hijack the authentication of arbi
MediumCVSS 6.0No exploitEPSS 1%twiki · twikiApr 30, 2009
- CVE-2006-429421Monitor
Directory traversal vulnerability in viewfile in TWiki 4.0.0 through 4.0.4 allows remote attackers to read arbitrary files via a ..
MediumCVSS 5.0Proof of conceptEPSS 4%twiki · twikiSep 8, 2006
- CVE-2007-519320Monitor
The default configuration for twiki 4.1.2 on Debian GNU/Linux, and possibly other operating systems, specifies the work area directory (cfg{
MediumCVSS 5.0No exploitEPSS 2%debian · debian linuxOct 4, 2007
- CVE-2006-294220Monitor
TWiki 4.0.0, 4.0.1, and 4.0.2 allows remote attackers to gain Twiki administrator privileges via a TWiki.TWikiRegistration form with a modif
MediumCVSS 5.1No exploitEPSS 2%twiki · twikiJun 20, 2006
- CVE-2011-301019Monitor
Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via
MediumCVSS 4.3Proof of conceptEPSS 5%twiki · twikiSep 30, 2011
- CVE-2010-384118Monitor
Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inject arbitrary web scr
MediumCVSS 4.3Proof of conceptEPSS 3%twiki · twikiOct 18, 2010
- CVE-2011-183818Monitor
Multiple cross-site scripting (XSS) vulnerabilities in TemplateLogin.pm in TWiki before 5.0.2 allow remote attackers to inject arbitrary web
MediumCVSS 4.3Proof of conceptEPSS 3%twiki · twikiMay 20, 2011
- CVE-2008-530418Monitor
Cross-site scripting (XSS) vulnerability in TWiki before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via the %URLPA
MediumCVSS 4.3Proof of conceptEPSS 2%twiki · twikiDec 9, 2008
- CVE-2012-097918Monitor
Cross-site scripting (XSS) vulnerability in TWiki allows remote attackers to inject arbitrary web script or HTML via the organization field
MediumCVSS 4.3No exploitEPSS 2%twiki · twikiFeb 2, 2012