Vulnerabilities > Tiddlywiki

DATE CVE VULNERABILITY TITLE RISK
2022-05-16 CVE-2022-29351 Unrestricted Upload of File with Dangerous Type vulnerability in Tiddlywiki Tiddlywiki5 5.2.2
An arbitrary file upload vulnerability in the file upload module of Tiddlywiki5 v5.2.2 allows attackers to execute arbitrary code via a crafted SVG file.
network
low complexity
tiddlywiki CWE-434
critical
9.8
2009-01-23 CVE-2008-5949 Code Injection vulnerability in Tiddlywiki Cctiddly 1.7.4/1.7.6
Multiple PHP remote file inclusion vulnerabilities in ccTiddly 1.7.4 and 1.7.6 allow remote attackers to execute arbitrary PHP code via a URL in the cct_base parameter to (1) index.php; (2) handle/proxy.php; (3) header.php, (4) include.php, and (5) workspace.php in includes/; and (6) plugins/RSS/files/rss.php.
network
low complexity
tiddlywiki CWE-94
7.5