Vulnerabilities > Foswiki > Foswiki > 1.1.3

DATE CVE VULNERABILITY TITLE RISK
2023-08-08 CVE-2023-33756 Path Traversal vulnerability in Foswiki
An issue in the SpreadSheetPlugin component of Foswiki v2.1.7 and below allows attackers to execute a directory traversal.
network
low complexity
foswiki CWE-22
7.5
2019-11-01 CVE-2013-1666 Code Injection vulnerability in Foswiki
Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro.
network
foswiki CWE-94
6.8
2013-01-04 CVE-2012-6330 Numeric Errors vulnerability in multiple products
The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to cause a denial of service (memory consumption) via a large integer in a %MAKETEXT% macro.
network
low complexity
twiki foswiki CWE-189
5.0
2012-02-08 CVE-2012-1004 Cross-Site Scripting vulnerability in Foswiki
Multiple cross-site scripting (XSS) vulnerabilities in UI/Register.pm in Foswiki before 1.1.5 allow remote authenticated users with CHANGE privileges to inject arbitrary web script or HTML via the (1) text, (2) FirstName, (3) LastName, (4) OrganisationName, (5) OrganisationUrl, (6) Profession, (7) Country, (8) State, (9) Address, (10) Location, (11) Telephone, (12) VoIP, (13) InstantMessagingIM, (14) Email, (15) HomePage, or (16) Comment parameter.
network
high complexity
foswiki CWE-79
2.1