Known Vulnerabilities for products from Twiki

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Twiki".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2018-20212 json bin/statistics in TWiki 6.0.2 allows cross-site scripting (XSS) via the webs parameter. 6.1 - MEDIUM 2019-03-21 2019-03-21
CVE-2014-9367 json Incomplete blacklist vulnerability in the urlEncode function in lib/TWiki.pm in TWiki 6.0.0 and 6.0.1 allows remote attackers... Not Provided 2014-12-31 2026-05-06
CVE-2014-9325 json Multiple cross-site scripting (XSS) vulnerabilities in TWiki 6.0.1 allow remote attackers to inject arbitrary web script or H... Not Provided 2014-12-31 2026-05-06
CVE-2014-7237 json lib/TWiki/Sandbox.pm in TWiki 6.0.0 and earlier, when running on Windows, allows remote attackers to bypass intended access r... Not Provided 2014-10-16 2026-05-06
CVE-2014-7236 json Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl ... 9.1 - CRITICAL 2020-02-17 2020-02-20
CVE-2013-1751 json TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter ... 9.8 - CRITICAL 2019-11-07 2019-11-08
CVE-2012-6330 json The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote... Not Provided 2013-01-04 2026-04-29
CVE-2012-0979 json Cross-site scripting (XSS) vulnerability in TWiki allows remote attackers to inject arbitrary web script or HTML via the orga... Not Provided 2012-02-02 2026-04-29
CVE-2011-3010 json Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow remote attackers to inject arbitrary web scri... Not Provided 2011-09-30 2026-04-29
CVE-2011-1838 json Multiple cross-site scripting (XSS) vulnerabilities in TemplateLogin.pm in TWiki before 5.0.2 allow remote attackers to injec... Not Provided 2011-05-20 2026-04-29
CVE-2010-3841 json Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inject ar... Not Provided 2010-10-18 2026-04-29
CVE-2009-4898 json Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.2 allows remote attackers to hijack the authentication of... Not Provided 2010-09-07 2026-04-29
CVE-2009-1339 json Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.1 allows remote authenticated users to hijack the authent... Not Provided 2009-04-30 2026-04-23
CVE-2008-5305 json Eval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% ... Not Provided 2008-12-10 2026-04-23
CVE-2008-5304 json Cross-site scripting (XSS) vulnerability in TWiki before 4.2.4 allows remote attackers to inject arbitrary web script or HTML... Not Provided 2008-12-10 2026-04-23
CVE-2008-4998 json postinst in twiki 4.1.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/twiki temporary file... Not Provided 2008-11-07 2026-04-23
CVE-2008-3195 json Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is sk... Not Provided 2008-09-18 2026-04-23
CVE-2007-5193 json The default configuration for twiki 4.1.2 on Debian GNU/Linux, and possibly other operating systems, specifies the work area ... Not Provided 2007-10-04 2026-04-23
CVE-2007-0669 json Unspecified vulnerability in Twiki 4.0.0 through 4.1.0 allows local users to execute arbitrary Perl code via unknown vectors ... Not Provided 2007-02-08 2026-04-23
CVE-2006-6071 json TWiki 4.0.5 and earlier, when running under Apache 1.3 using ApacheLogin with sessions and "ErrorDocument 401" redirects to a... Not Provided 2006-12-02 2026-04-23

Known software with vulnerabilities from Twiki

Type Vendor Product Version
ApplicationTwikiTwiki-
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report