VYPR

Wikiwig

by Wikiwig

CVEs (2)

  • CVE-2011-5267Nov 5, 2013
    risk 0.04cvss epss 0.10

    Multiple cross-site scripting (XSS) vulnerabilities in spell-check-savedicts.php in the SpellChecker module in Xinha, as used in WikiWig 5.01 and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) to_p_dict or (2) to_r_list parameter. NOTE: this issue might be related to the htmlarea plugin and CVE-2013-5670.

  • CVE-2006-2888Jun 7, 2006
    risk 0.03cvss epss 0.06

    PHP remote file inclusion vulnerability in _wk/wk_lang.php in Wikiwig 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the WK[wkPath] parameter.