Known Vulnerabilities for products from Foswiki
Listed below are 8 of the newest known vulnerabilities associated with the vendor "Foswiki".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-33756 json | An issue in the SpreadSheetPlugin component of Foswiki v2.1.7 and below allows attackers to execute a directory traversal. | 7.5 - HIGH | 2023-08-08 | 2023-08-14 |
| CVE-2023-24698 json | Insufficient parameter validation in the Foswiki::Sandbox component of Foswiki v2.1.7 and below allows attackers to perform a... | 7.5 - HIGH | 2023-08-08 | 2023-08-15 |
| CVE-2013-1666 json | Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro. | 9.8 - CRITICAL | 2019-11-01 | 2019-11-08 |
| CVE-2012-6330 json | The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote... | Not Provided | 2013-01-04 | 2026-04-29 |
| CVE-2012-1004 json | Multiple cross-site scripting (XSS) vulnerabilities in UI/Register.pm in Foswiki before 1.1.5 allow remote authenticated user... | Not Provided | 2012-02-08 | 2026-04-29 |
| CVE-2010-4215 json | UI/Manage.pm in Foswiki 1.1.0 and 1.1.1 allows remote authenticated users to gain privileges by modifying the GROUP and ALLOW... | Not Provided | 2010-11-17 | 2026-04-29 |
| CVE-2009-4853 json | Multiple cross-site scripting (XSS) vulnerabilities in JumpBox before 1.1.2 for Foswiki Wiki System allow remote attackers to... | Not Provided | 2010-05-07 | 2026-04-29 |
| CVE-2009-1434 json | Cross-site request forgery (CSRF) vulnerability in Foswiki before 1.0.5 allows remote attackers to hijack the authentication ... | Not Provided | 2009-04-30 | 2026-04-23 |
Known software with vulnerabilities from Foswiki
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Foswiki | Foswiki | 1.0.0 |