Vulnerabilities > Foswiki

DATE CVE VULNERABILITY TITLE RISK
2023-08-08 CVE-2023-24698 Path Traversal vulnerability in Foswiki
Insufficient parameter validation in the Foswiki::Sandbox component of Foswiki v2.1.7 and below allows attackers to perform a directory traversal via supplying a crafted web request.
network
low complexity
foswiki CWE-22
7.5
2023-08-08 CVE-2023-33756 Path Traversal vulnerability in Foswiki
An issue in the SpreadSheetPlugin component of Foswiki v2.1.7 and below allows attackers to execute a directory traversal.
network
low complexity
foswiki CWE-22
7.5
2019-11-01 CVE-2013-1666 Code Injection vulnerability in Foswiki
Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro.
network
low complexity
foswiki CWE-94
critical
9.8