Foswiki
Products
1- 8 CVEs
Recent CVEs
8| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2012-6330 | 0.06 | — | 0.36 | Jan 4, 2013 | The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to cause a denial of service (memory consumption) via a large integer in a %MAKETEXT% macro. | |||
| CVE-2026-2861 | 0.00 | — | 0.00 | Feb 21, 2026 | A vulnerability was detected in Foswiki up to 2.1.10. The affected element is an unknown function of the component Changes/Viewfile/Oops. The manipulation results in information disclosure. It is possible to launch the attack remotely. The exploit is now public and may be used.… | |||
| CVE-2023-33756 | 0.00 | — | 0.01 | Aug 8, 2023 | An issue in the SpreadSheetPlugin component of Foswiki v2.1.7 and below allows attackers to execute a directory traversal. | |||
| CVE-2023-24698 | 0.00 | — | 0.01 | Aug 8, 2023 | Insufficient parameter validation in the Foswiki::Sandbox component of Foswiki v2.1.7 and below allows attackers to perform a directory traversal via supplying a crafted web request. | |||
| CVE-2013-1666 | 0.00 | — | 0.02 | Nov 1, 2019 | Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro. | |||
| CVE-2012-1004 | 0.00 | — | 0.01 | Feb 8, 2012 | Multiple cross-site scripting (XSS) vulnerabilities in UI/Register.pm in Foswiki before 1.1.5 allow remote authenticated users with CHANGE privileges to inject arbitrary web script or HTML via the (1) text, (2) FirstName, (3) LastName, (4) OrganisationName, (5) OrganisationUrl,… | |||
| CVE-2010-4215 | 0.00 | — | 0.01 | Nov 17, 2010 | UI/Manage.pm in Foswiki 1.1.0 and 1.1.1 allows remote authenticated users to gain privileges by modifying the GROUP and ALLOWTOPICCHANGE preferences in the topic preferences for Main.AdminGroup. | |||
| CVE-2009-1434 | 0.00 | — | 0.01 | Apr 30, 2009 | Cross-site request forgery (CSRF) vulnerability in Foswiki before 1.0.5 allows remote attackers to hijack the authentication of arbitrary users for requests that modify pages, change permissions, or change group memberships, as demonstrated by a URL for a (1) save or (2) view… |
- CVE-2012-6330Jan 4, 2013risk 0.06cvss —epss 0.36
The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to cause a denial of service (memory consumption) via a large integer in a %MAKETEXT% macro.
- CVE-2026-2861Feb 21, 2026risk 0.00cvss —epss 0.00
A vulnerability was detected in Foswiki up to 2.1.10. The affected element is an unknown function of the component Changes/Viewfile/Oops. The manipulation results in information disclosure. It is possible to launch the attack remotely. The exploit is now public and may be used.…
- CVE-2023-33756Aug 8, 2023risk 0.00cvss —epss 0.01
An issue in the SpreadSheetPlugin component of Foswiki v2.1.7 and below allows attackers to execute a directory traversal.
- CVE-2023-24698Aug 8, 2023risk 0.00cvss —epss 0.01
Insufficient parameter validation in the Foswiki::Sandbox component of Foswiki v2.1.7 and below allows attackers to perform a directory traversal via supplying a crafted web request.
- CVE-2013-1666Nov 1, 2019risk 0.00cvss —epss 0.02
Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro.
- CVE-2012-1004Feb 8, 2012risk 0.00cvss —epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in UI/Register.pm in Foswiki before 1.1.5 allow remote authenticated users with CHANGE privileges to inject arbitrary web script or HTML via the (1) text, (2) FirstName, (3) LastName, (4) OrganisationName, (5) OrganisationUrl,…
- CVE-2010-4215Nov 17, 2010risk 0.00cvss —epss 0.01
UI/Manage.pm in Foswiki 1.1.0 and 1.1.1 allows remote authenticated users to gain privileges by modifying the GROUP and ALLOWTOPICCHANGE preferences in the topic preferences for Main.AdminGroup.
- CVE-2009-1434Apr 30, 2009risk 0.00cvss —epss 0.01
Cross-site request forgery (CSRF) vulnerability in Foswiki before 1.0.5 allows remote attackers to hijack the authentication of arbitrary users for requests that modify pages, change permissions, or change group memberships, as demonstrated by a URL for a (1) save or (2) view…