Vulnerabilities > Pmwiki

DATE CVE VULNERABILITY TITLE RISK
2020-02-05 CVE-2010-4662 Cross-site Scripting vulnerability in Pmwiki
PmWiki before 2.2.21 has XSS.
network
pmwiki CWE-79
4.3
2011-12-22 CVE-2011-4453 Code Injection vulnerability in Pmwiki
The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitrary code via PHP sequences in a crafted order parameter in a pagelist directive, leading to unintended use of the PHP create_function function.
network
low complexity
pmwiki CWE-94
7.5
2011-03-01 CVE-2010-4748 Cross-Site Scripting vulnerability in Pmwiki 2.2.20
Cross-site scripting (XSS) vulnerability in pmwiki.php in PmWiki 2.2.20 allows remote attackers to inject arbitrary web script or HTML via the from parameter to Main/WikiSandbox.
network
pmwiki CWE-79
4.3
2010-05-12 CVE-2010-1481 Cross-Site Scripting vulnerability in Pmwiki 2.2.15
Cross-site scripting (XSS) vulnerability in the table feature in PmWiki 2.2.15 allows remote authenticated users to inject arbitrary web script or HTML via the width attribute.
network
pmwiki CWE-79
3.5
2006-08-30 CVE-2006-4453 HTML Injection vulnerability in PMWiki Table Markups
Cross-site scripting (XSS) vulnerability in PmWiki before 2.1.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "table markups".
network
pmwiki
4.3
2006-06-06 CVE-2006-2840 Cross-Site Scripting vulnerability in PmWiki
Cross-site scripting (XSS) vulnerability in (1) uploads.php and (2) "url links" in PmWiki 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
network
pmwiki
6.8
2006-01-31 CVE-2006-0479 Input Validation vulnerability in Pmwiki 2.1Beta20
pmwiki.php in PmWiki 2.1 beta 20, with register_globals enabled, allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GPC variable and a GLOBALS[] variable with the same name, which causes PmWiki to unset the GLOBALS[] variable but not the GPC variable, which creates resultant vulnerabilities such as remote file inclusion and cross-site scripting (XSS).
network
pmwiki
4.3
2005-11-27 CVE-2005-3849 Cross-Site Scripting vulnerability in PmWiki Search
Cross-site scripting (XSS) vulnerability in the Search module in PmWiki up to 2.0.12 allows remote attackers to inject arbitrary web script or HTML via the q parameter.
network
pmwiki
4.3