foswiki kayıtları
foswiki üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %11,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-189 Numeric Errors1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
- CWE-264 Permissions, Privileges, and Access Controls1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2013-1666İstismar yok | Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro.foswiki · foswiki · CWE-94 | Kritik9,8 | — | %2,3 | 1 Kas 2019 |
31İzleyin | CVE-2012-6330Kavram kanıtı | The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to ctwiki · twiki · CWE-189 | Orta5,0 | — | %35,7 | 4 Oca 2013 |
30İzleyin | CVE-2023-33756İstismar yok | An issue in the SpreadSheetPlugin component of Foswiki v2.1.7 and below allows attackers to execute a directory traversal.foswiki · foswiki · CWE-22 | Yüksek7,5 | — | %1,1 | 8 Ağu 2023 |
30İzleyin | CVE-2023-24698İstismar yok | Insufficient parameter validation in the Foswiki::Sandbox component of Foswiki v2.1.7 and below allows attackers to perform a directory travfoswiki · foswiki · CWE-22 | Yüksek7,5 | — | %0,8 | 8 Ağu 2023 |
27İzleyin | CVE-2009-1434İstismar yok | Cross-site request forgery (CSRF) vulnerability in Foswiki before 1.0.5 allows remote attackers to hijack the authentication of arbitrary usfoswiki · foswiki · CWE-352 | Orta6,8 | — | %0,7 | 30 Nis 2009 |
26İzleyin | CVE-2010-4215İstismar yok | UI/Manage.pm in Foswiki 1.1.0 and 1.1.1 allows remote authenticated users to gain privileges by modifying the GROUP and ALLOWTOPICCHANGE prefoswiki · foswiki · CWE-264 | Orta6,5 | — | %1,1 | 16 Kas 2010 |
22İzleyin | CVE-2026-2861İstismar yok | Foswiki Changes/Viewfile/Oops information disclosurefoswiki · foswiki · CWE-200 | Orta5,5 | — | %0,7 | 21 Şub 2026 |
17İzleyin | CVE-2009-4853İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in JumpBox before 1.1.2 for Foswiki Wiki System allow remote attackers to inject arbitrajumpbox · jumpbox · CWE-79 | Orta4,3 | — | %1,0 | 7 May 2010 |
8İzleyin | CVE-2012-1004İstismar yok | Multiple cross-site scripting (XSS) vulnerabilities in UI/Register.pm in Foswiki before 1.1.5 allow remote authenticated users with CHANGE pfoswiki · foswiki · CWE-79 | Düşük2,1 | — | %1,3 | 8 Şub 2012 |
- CVE-2013-166640Planlayın
Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro.
KritikCVSS 9,8İstismar yokEPSS %2foswiki · foswiki1 Kas 2019
- CVE-2012-633031İzleyin
The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to c
OrtaCVSS 5,0Kavram kanıtıEPSS %36twiki · twiki4 Oca 2013
- CVE-2023-3375630İzleyin
An issue in the SpreadSheetPlugin component of Foswiki v2.1.7 and below allows attackers to execute a directory traversal.
YüksekCVSS 7,5İstismar yokEPSS %1foswiki · foswiki8 Ağu 2023
- CVE-2023-2469830İzleyin
Insufficient parameter validation in the Foswiki::Sandbox component of Foswiki v2.1.7 and below allows attackers to perform a directory trav
YüksekCVSS 7,5İstismar yokEPSS %1foswiki · foswiki8 Ağu 2023
- CVE-2009-143427İzleyin
Cross-site request forgery (CSRF) vulnerability in Foswiki before 1.0.5 allows remote attackers to hijack the authentication of arbitrary us
OrtaCVSS 6,8İstismar yokEPSS %1foswiki · foswiki30 Nis 2009
- CVE-2010-421526İzleyin
UI/Manage.pm in Foswiki 1.1.0 and 1.1.1 allows remote authenticated users to gain privileges by modifying the GROUP and ALLOWTOPICCHANGE pre
OrtaCVSS 6,5İstismar yokEPSS %1foswiki · foswiki16 Kas 2010
- CVE-2026-286122İzleyin
Foswiki Changes/Viewfile/Oops information disclosure
OrtaCVSS 5,5İstismar yokEPSS %1foswiki · foswiki21 Şub 2026
- CVE-2009-485317İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in JumpBox before 1.1.2 for Foswiki Wiki System allow remote attackers to inject arbitra
OrtaCVSS 4,3İstismar yokEPSS %1jumpbox · jumpbox7 May 2010
- CVE-2012-10048İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in UI/Register.pm in Foswiki before 1.1.5 allow remote authenticated users with CHANGE p
DüşükCVSS 2,1İstismar yokEPSS %1foswiki · foswiki8 Şub 2012