Vulnerabilities > Pmwiki > Pmwiki > 2.1.4

DATE CVE VULNERABILITY TITLE RISK
2020-02-05 CVE-2010-4662 Cross-site Scripting vulnerability in Pmwiki
PmWiki before 2.2.21 has XSS.
network
pmwiki CWE-79
4.3
2011-12-22 CVE-2011-4453 Code Injection vulnerability in Pmwiki
The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitrary code via PHP sequences in a crafted order parameter in a pagelist directive, leading to unintended use of the PHP create_function function.
network
low complexity
pmwiki CWE-94
7.5
2006-08-30 CVE-2006-4453 HTML Injection vulnerability in PMWiki Table Markups
Cross-site scripting (XSS) vulnerability in PmWiki before 2.1.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "table markups".
network
pmwiki
4.3
2006-06-06 CVE-2006-2840 Cross-Site Scripting vulnerability in PmWiki
Cross-site scripting (XSS) vulnerability in (1) uploads.php and (2) "url links" in PmWiki 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
network
pmwiki
6.8