CVE-2025-61224Cross-site Scripting in Dokuwiki

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 84.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 6

Description

Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitrary code via the q parameter

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

debiandebian/dokuwiki< dokuwiki 2025-05-14.b+dfsg-1 (forky)
Debiandokuwiki/dokuwiki< 2025-05-14.b+dfsg-1

🔴Vulnerability Details

2
GHSA
GHSA-pp4p-g4w7-gvp7: Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[562025-10-06
OSV
CVE-2025-61224: Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[562025-10-06

📋Vendor Advisories

1
Debian
CVE-2025-61224: dokuwiki - Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] all...2025