cbcvebase.
CVE-2024-28865
published 2024-03-18

CVE-2024-28865: django-wiki is a wiki system for Django. Installations of django-wiki prior to version 0.10.1 are vulnerable to maliciously crafted article content that can…

PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.61%
47.8th percentile
django-wiki is a wiki system for Django. Installations of django-wiki prior to version 0.10.1 are vulnerable to maliciously crafted article content that can cause severe use of server CPU through a regular expression loop. Version 0.10.1 fixes this issue. As a workaround, close off access to create and edit articles by anonymous users.

Affected

3 ranges
VendorProductVersion rangeFixed in
django-wikidjango-wiki< 0.10.10.10.1
django-wiki_projectdjango-wiki< 0.10.10.10.1
requarkswiki>= 0 < 0.10.10.10.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.