CVE-2025-61224
- EPSS 0.06%
- Veröffentlicht 06.10.2025 00:00:00
- Zuletzt bearbeitet 06.10.2025 16:15:34
Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitrary code via the q parameter
CVE-2024-33103
- EPSS 0.06%
- Veröffentlicht 30.04.2024 18:15:19
- Zuletzt bearbeitet 21.11.2024 09:16:31
An arbitrary file upload vulnerability in the Media Manager component of DokuWiki 2024-02-06a allows attackers to execute arbitrary code by uploading a crafted SVG file. NOTE: as noted in the 4267 issue reference, there is a position that exploitabil...
CVE-2023-34408
- EPSS 0.32%
- Veröffentlicht 05.06.2023 02:15:09
- Zuletzt bearbeitet 08.01.2025 20:15:26
DokuWiki before 2023-04-04a allows XSS via RSS titles.
CVE-2022-3123
- EPSS 0.59%
- Veröffentlicht 05.09.2022 10:15:09
- Zuletzt bearbeitet 21.11.2024 07:18:52
Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a.
CVE-2022-28919
- EPSS 0.53%
- Veröffentlicht 12.05.2022 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:58:11
HTMLCreator release_stable_2020-07-29 was discovered to contain a cross-site scripting (XSS) vulnerability via the function _generateFilename.
CVE-2018-15474
- EPSS 1.07%
- Veröffentlicht 07.09.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:50:53
CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remote attackers to exfiltrate sensitive data and to execute arbitrary code via a value that is mishandled...
CVE-2017-18123
- EPSS 0.35%
- Veröffentlicht 03.02.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:19:23
The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does not properly encode user input, which leads to a reflected file download vulnerability, and allows remote attackers to run arbitrary programs.
CVE-2017-12980
- EPSS 0.54%
- Veröffentlicht 21.08.2017 07:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
DokuWiki through 2017-02-19c has stored XSS when rendering a malicious RSS or Atom feed, in /inc/parser/xhtml.php. An attacker can create or edit a wiki that uses RSS or Atom data from an attacker-controlled server to trigger JavaScript execution. Th...
CVE-2017-12979
- EPSS 0.54%
- Veröffentlicht 21.08.2017 07:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
DokuWiki through 2017-02-19c has stored XSS when rendering a malicious language name in a code element, in /inc/parser/xhtml.php. An attacker can create or edit a wiki with this element to trigger JavaScript execution.
CVE-2017-12583
- EPSS 3.23%
- Veröffentlicht 06.08.2017 03:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
DokuWiki through 2017-02-19b has XSS in the at parameter (aka the DATE_AT variable) to doku.php.