moinmo records
26 published records for vendor moinmo.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 3.8%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')12
- CWE-264 Permissions, Privileges, and Access Controls4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-16 Configuration1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
26 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2020-25074No exploit | The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request.moinmo · moinmoin · CWE-22 | Critical9.8 | — | 6.6% | Nov 10, 2020 |
35Monitor | CVE-2012-6081Weaponized | Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actmoinmo · moinmoin | Medium6.0 | — | 35.3% | Jan 2, 2013 |
31Monitor | CVE-2009-4762No exploit | MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchicmoinmo · moinmoin · CWE-264 | High7.5 | — | 3.1% | Mar 29, 2010 |
31Monitor | CVE-2010-0717No exploit | The default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does not prevent unsafe package actions, which has umoinmo · moinmoin · CWE-16 | High7.5 | — | 2.0% | Feb 26, 2010 |
31Monitor | CVE-2010-0669No exploit | MoinMoin before 1.8.7 and 1.9.x before 1.9.2 does not properly sanitize user profiles, which has unspecified impact and attack vectors.moinmo · moinmoin | High7.5 | — | 1.9% | Feb 26, 2010 |
30Monitor | CVE-2012-6495Proof of concept | Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions moinmo · moinmoin · CWE-22 | Medium6.0 | — | 18.7% | Jan 2, 2013 |
28Monitor | CVE-2010-0668No exploit | Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors,moinmo · moinmoin | Medium6.8 | — | 2.2% | Feb 26, 2010 |
27Monitor | CVE-2008-6603No exploit | MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote attackers to bypassmoinmo · moinmoin · CWE-264 | Medium6.8 | — | 1.7% | Apr 3, 2009 |
26Monitor | CVE-2012-6080No exploit | Directory traversal vulnerability in the _do_attachment_move function in the AttachFile action (action/AttachFile.py) in MoinMoin 1.9.3 thromoinmo · moinmoin · CWE-22 | Medium6.4 | — | 4.1% | Jan 2, 2013 |
25Monitor | CVE-2012-4404No exploit | security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Knomoinmo · moinmoin · CWE-264 | Medium6.0 | — | 2.1% | Sep 10, 2012 |
25Monitor | CVE-2017-5934No exploit | Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbimoinmo · moinmoin · CWE-79 | Medium6.1 | — | 1.9% | Oct 15, 2018 |
24Monitor | CVE-2016-9119No exploit | Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbitmoinmo · moinmoin · CWE-79 | Medium6.1 | — | 1.5% | Jan 30, 2017 |
24Monitor | CVE-2016-7146No exploit | MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation or crafted URL" approach, relatmoinmo · moinmoin · CWE-79 | Medium6.1 | — | 1.2% | Nov 10, 2016 |
24Monitor | CVE-2016-7148No exploit | MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross moinmo · moinmoin · CWE-79 | Medium6.1 | — | 1.2% | Nov 10, 2016 |
22Monitor | CVE-2020-15275No exploit | malicious SVG attachment causing stored XSS vulnerability in MoinMoinmoinmo · moinmoin · CWE-79 | Medium5.4 | — | 1.7% | Nov 11, 2020 |
21Monitor | CVE-2010-1238No exploit | MoinMoin 1.7.1 allows remote attackers to bypass the textcha protection mechanism by modifying the textcha-question and textcha-answer fieldmoinmo · moinmoin · CWE-264 | Medium5.0 | — | 2.0% | Apr 5, 2010 |
21Monitor | CVE-2010-0667No exploit | MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environmentmoinmo · moinmoin · CWE-200 | Medium5.0 | — | 1.9% | Feb 26, 2010 |
20Monitor | CVE-2008-6549No exploit | The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are nomoinmo · moinmoin | Medium5.0 | — | 1.5% | Mar 29, 2009 |
20Monitor | CVE-2008-6548No exploit | The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorizemoinmo · moinmoin · CWE-862 | Medium5.0 | — | 1.0% | Mar 29, 2009 |
18Monitor | CVE-2010-2487No exploit | Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, 1.8.x before 1.8.8, and 1.9.x before 1.9.3 allow remote amoinmo · moinmoin · CWE-79 | Medium4.3 | — | 2.7% | Aug 5, 2010 |
18Monitor | CVE-2010-2970No exploit | Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.9.x before 1.9.3 allow remote attackers to inject arbitrary web script or moinmo · moinmoin · CWE-79 | Medium4.3 | — | 2.6% | Aug 5, 2010 |
18Monitor | CVE-2010-2969No exploit | Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, and 1.9.x before 1.9.3, allow remote attackers to inject moinmo · moinmoin · CWE-79 | Medium4.3 | — | 2.6% | Aug 5, 2010 |
18Monitor | CVE-2009-1482No exploit | Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote attackers to inject amoinmo · moinmoin · CWE-79 | Medium4.3 | — | 2.5% | Apr 29, 2009 |
18Monitor | CVE-2012-6082No exploit | Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject armoinmo · moinmoin · CWE-79 | Medium4.3 | — | 2.1% | Jan 2, 2013 |
15Monitor | CVE-2010-0828No exploit | Cross-site scripting (XSS) vulnerability in action/Despam.py in the Despam action module in MoinMoin 1.8.7 and 1.9.2 allows remote authenticmoinmo · moinmoin · CWE-79 | Low3.5 | — | 2.3% | Apr 5, 2010 |
- CVE-2020-2507441Plan
The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request.
CriticalCVSS 9.8No exploitEPSS 7%moinmo · moinmoinNov 10, 2020
- CVE-2012-608135Monitor
Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) act
MediumCVSS 6.0WeaponizedEPSS 35%moinmo · moinmoinJan 2, 2013
- CVE-2009-476231Monitor
MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchic
HighCVSS 7.5No exploitEPSS 3%moinmo · moinmoinMar 29, 2010
- CVE-2010-071731Monitor
The default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does not prevent unsafe package actions, which has u
HighCVSS 7.5No exploitEPSS 2%moinmo · moinmoinFeb 26, 2010
- CVE-2010-066931Monitor
MoinMoin before 1.8.7 and 1.9.x before 1.9.2 does not properly sanitize user profiles, which has unspecified impact and attack vectors.
HighCVSS 7.5No exploitEPSS 2%moinmo · moinmoinFeb 26, 2010
- CVE-2012-649530Monitor
Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions
MediumCVSS 6.0Proof of conceptEPSS 19%moinmo · moinmoinJan 2, 2013
- CVE-2010-066828Monitor
Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors,
MediumCVSS 6.8No exploitEPSS 2%moinmo · moinmoinFeb 26, 2010
- CVE-2008-660327Monitor
MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote attackers to bypass
MediumCVSS 6.8No exploitEPSS 2%moinmo · moinmoinApr 3, 2009
- CVE-2012-608026Monitor
Directory traversal vulnerability in the _do_attachment_move function in the AttachFile action (action/AttachFile.py) in MoinMoin 1.9.3 thro
MediumCVSS 6.4No exploitEPSS 4%moinmo · moinmoinJan 2, 2013
- CVE-2012-440425Monitor
security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Kno
MediumCVSS 6.0No exploitEPSS 2%moinmo · moinmoinSep 10, 2012
- CVE-2017-593425Monitor
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbi
MediumCVSS 6.1No exploitEPSS 2%moinmo · moinmoinOct 15, 2018
- CVE-2016-911924Monitor
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbit
MediumCVSS 6.1No exploitEPSS 1%moinmo · moinmoinJan 30, 2017
- CVE-2016-714624Monitor
MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation or crafted URL" approach, relat
MediumCVSS 6.1No exploitEPSS 1%moinmo · moinmoinNov 10, 2016
- CVE-2016-714824Monitor
MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross
MediumCVSS 6.1No exploitEPSS 1%moinmo · moinmoinNov 10, 2016
- CVE-2020-1527522Monitor
malicious SVG attachment causing stored XSS vulnerability in MoinMoin
MediumCVSS 5.4No exploitEPSS 2%moinmo · moinmoinNov 11, 2020
- CVE-2010-123821Monitor
MoinMoin 1.7.1 allows remote attackers to bypass the textcha protection mechanism by modifying the textcha-question and textcha-answer field
MediumCVSS 5.0No exploitEPSS 2%moinmo · moinmoinApr 5, 2010
- CVE-2010-066721Monitor
MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment
MediumCVSS 5.0No exploitEPSS 2%moinmo · moinmoinFeb 26, 2010
- CVE-2008-654920Monitor
The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are no
MediumCVSS 5.0No exploitEPSS 1%moinmo · moinmoinMar 29, 2009
- CVE-2008-654820Monitor
The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorize
MediumCVSS 5.0No exploitEPSS 1%moinmo · moinmoinMar 29, 2009
- CVE-2010-248718Monitor
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, 1.8.x before 1.8.8, and 1.9.x before 1.9.3 allow remote a
MediumCVSS 4.3No exploitEPSS 3%moinmo · moinmoinAug 5, 2010
- CVE-2010-297018Monitor
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.9.x before 1.9.3 allow remote attackers to inject arbitrary web script or
MediumCVSS 4.3No exploitEPSS 3%moinmo · moinmoinAug 5, 2010
- CVE-2010-296918Monitor
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, and 1.9.x before 1.9.3, allow remote attackers to inject
MediumCVSS 4.3No exploitEPSS 3%moinmo · moinmoinAug 5, 2010
- CVE-2009-148218Monitor
Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote attackers to inject a
MediumCVSS 4.3No exploitEPSS 3%moinmo · moinmoinApr 29, 2009
- CVE-2012-608218Monitor
Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject ar
MediumCVSS 4.3No exploitEPSS 2%moinmo · moinmoinJan 2, 2013
- CVE-2010-082815Monitor
Cross-site scripting (XSS) vulnerability in action/Despam.py in the Despam action module in MoinMoin 1.8.7 and 1.9.2 allows remote authentic
LowCVSS 3.5No exploitEPSS 2%moinmo · moinmoinApr 5, 2010