Debian Dokuwiki vulnerabilities
34 known vulnerabilities affecting debian/dokuwiki.
Total CVEs
34
CISA KEV
0
Public exploits
5
Exploited in wild
1
Severity breakdown
HIGH2MEDIUM18LOW14
Vulnerabilities
Page 1 of 2
CVE-2010-0288P2MEDIUMCVSS 7.5ExploitedPoCfixed in dokuwiki 0.0.20090214b-3.1 (bookworm)2010
CVE-2010-0288 [HIGH] CVE-2010-0288: dokuwiki - A typo in the administrator permission check in the ACL Manager plugin (plugins/...
A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to gain privileges and access closed wikis by editing current ACL statements, as demonstrated in the wild in January 2010.
Scope: local
bookworm: resolved (fixed in 0.0.20090214b-3.1)
bullseye: resolved (fixed in 0.0.200
debian
CVE-2009-1960P2LOWCVSS 9.3PoCfixed in dokuwiki 0.0.20090214b-1 (bookworm)2009
CVE-2009-1960 [CRITICAL] CVE-2009-1960: dokuwiki - inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when regist...
inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. NOTE: PHP remote file inclusion is also possible in PHP 5 using ftp:// URLs.
Scope: local
bookworm: resolved (fixed in 0.0.2009021
debian
CVE-2025-61224P3MEDIUMCVSS 6.5PoCfixed in dokuwiki 2025-05-14.b+dfsg-1 (forky)2025
CVE-2025-61224 [MEDIUM] CVE-2025-61224: dokuwiki - Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] all...
Cross Site Scripting vulnerability in DokuWiki 2025-05-14a 'Librarian'[56.1] allows a remote attacker to execute arbitrary code via the q parameter
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2025-05-14.b+dfsg-1)
sid: resolved (fixed in 2025-05-14.b+dfsg-1)
trixie: open
debian
CVE-2010-0287P3LOWCVSS 5.0PoCfixed in dokuwiki 0.0.20090214b-3.1 (bookworm)2010
CVE-2010-0287 [MEDIUM] CVE-2010-0287: dokuwiki - Directory traversal vulnerability in the ACL Manager plugin (plugins/acl/ajax.ph...
Directory traversal vulnerability in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to list the contents of arbitrary directories via a .. (dot dot) in the ns parameter.
Scope: local
bookworm: resolved (fixed in 0.0.20090214b-3.1)
bullseye: resolved (fixed in 0.0.20090214b-3.1)
forky: resolved (fixed in 0.0.2009
debian
CVE-2017-12583P3MEDIUMCVSS 6.1PoCfixed in dokuwiki 0.0.20180422.a-1 (bookworm)2017
CVE-2017-12583 [MEDIUM] CVE-2017-12583: dokuwiki - DokuWiki through 2017-02-19b has XSS in the at parameter (aka the DATE_AT variab...
DokuWiki through 2017-02-19b has XSS in the at parameter (aka the DATE_AT variable) to doku.php.
Scope: local
bookworm: resolved (fixed in 0.0.20180422.a-1)
bullseye: resolved (fixed in 0.0.20180422.a-1)
forky: resolved (fixed in 0.0.20180422.a-1)
sid: resolved (fixed in 0.0.20180422.a-1)
trixie: resolved (fixed in 0.0.20180422.a-1)
debian
CVE-2006-2878P3HIGHCVSS 7.5fixed in dokuwiki 0.0.20060309-4 (bookworm)2006
CVE-2006-2878 [HIGH] CVE-2006-2878: dokuwiki - The spellchecker (spellcheck.php) in DokuWiki 2006/06/04 and earlier allows remo...
The spellchecker (spellcheck.php) in DokuWiki 2006/06/04 and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" that is inserted into a regular expression that is processed by preg_replace with the /e (executable) modifier.
Scope: local
bookworm: resolved (fixed in 0.0.20060309-4)
bullseye: resolved (fixed in 0.0.20060
debian
CVE-2016-7964P3LOWCVSS 8.6fixed in dokuwiki 2024-02-06b+dfsg-7 (forky)2016
CVE-2016-7964 [HIGH] CVE-2016-7964: dokuwiki - The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php in DokuWi...
The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php in DokuWiki 2016-06-26a and older, when media file fetching is enabled, has no way to restrict access to private networks. This allows users to scan ports of internal networks via SSRF, such as 10.0.0.1/8, 172.16.0.0/12, and 192.168.0.0/16.
Scope: local
bookworm: open
bullseye: open
forky: resolve
debian
CVE-2017-18123P3HIGHCVSS 8.6fixed in dokuwiki 0.0.20160626.a-2.1 (bookworm)2017
CVE-2017-18123 [HIGH] CVE-2017-18123: dokuwiki - The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does not...
The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does not properly encode user input, which leads to a reflected file download vulnerability, and allows remote attackers to run arbitrary programs.
Scope: local
bookworm: resolved (fixed in 0.0.20160626.a-2.1)
bullseye: resolved (fixed in 0.0.20160626.a-2.1)
forky: resolved (fixed in 0.0.201606
debian
CVE-2006-4674P3MEDIUMCVSS 7.5fixed in dokuwiki 0.0.20060309-5.1 (bookworm)2006
CVE-2006-4674 [HIGH] CVE-2006-4674: dokuwiki - Direct static code injection vulnerability in doku.php in DokuWiki before 2006-0...
Direct static code injection vulnerability in doku.php in DokuWiki before 2006-030-09c allows remote attackers to execute arbitrary PHP code via the X-FORWARDED-FOR HTTP header, which is stored in config.php.
Scope: local
bookworm: resolved (fixed in 0.0.20060309-5.1)
bullseye: resolved (fixed in 0.0.20060309-5.1)
forky: resolved (fixed in 0.0.20060309-5.1)
sid: reso
debian
CVE-2006-5099P3MEDIUMCVSS 7.5fixed in dokuwiki 0.0.20060309-5.2 (bookworm)2006
CVE-2006-5099 [HIGH] CVE-2006-5099: dokuwiki - lib/exec/fetch.php in DokuWiki before 2006-03-09e, when conf[imconvert] is confi...
lib/exec/fetch.php in DokuWiki before 2006-03-09e, when conf[imconvert] is configured to use ImageMagick, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) w and (2) h parameters, which are not filtered when invoking convert.
Scope: local
bookworm: resolved (fixed in 0.0.20060309-5.2)
bullseye: resolved (fixed in 0.0.20060309-5
debian
CVE-2014-8763P3MEDIUMCVSS 5.0fixed in dokuwiki 0.0.20140929.a-1 (bookworm)2014
CVE-2014-8763 [MEDIUM] CVE-2014-8763: dokuwiki - DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication...
DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password starting with a null (\0) character and a valid user name, which triggers an unauthenticated bind.
Scope: local
bookworm: resolved (fixed in 0.0.20140929.a-1)
bullseye: resolved (fixed in 0.0.20140929.a-1)
forky: resolved
debian
CVE-2006-4675P3MEDIUMCVSS 7.5fixed in dokuwiki 0.0.20060309-5.1 (bookworm)2006
CVE-2006-4675 [HIGH] CVE-2006-4675: dokuwiki - Unrestricted file upload vulnerability in lib/exe/media.php in DokuWiki before 2...
Unrestricted file upload vulnerability in lib/exe/media.php in DokuWiki before 2006-03-09c allows remote attackers to upload executable files into the data/media folder via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.0.20060309-5.1)
bullseye: resolved (fixed in 0.0.20060309-5.1)
forky: resolved (fixed in 0.0.20060309-5.1)
sid: resolved (fixed in
debian
CVE-2014-8764P3MEDIUMCVSS 5.0fixed in dokuwiki 0.0.20140929.a-1 (bookworm)2014
CVE-2014-8764 [MEDIUM] CVE-2014-8764: dokuwiki - DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentic...
DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a user name and password starting with a null (\0) character, which triggers an anonymous bind.
Scope: local
bookworm: resolved (fixed in 0.0.20140929.a-1)
bullseye: resolved (fixed in 0.0.20140929.a-1)
forky: resolved (fixed i
debian
CVE-2015-2172P4MEDIUMCVSS 6.5fixed in dokuwiki 0.0.20140929.d-1 (bookworm)2015
CVE-2015-2172 [MEDIUM] CVE-2015-2172: dokuwiki - DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permi...
DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain privileges and add or delete ACL rules via a request to the XMLRPC API.
Scope: local
bookworm: resolved (fixed in 0.0.20140929.d-1)
bullseye: resolved (fixed in 0.0.20140929.d-1)
forky: resolved (fixed in 0.0.20
debian
CVE-2016-7965P4LOWCVSS 6.5fixed in dokuwiki 2024-02-06b+dfsg-7 (forky)2016
CVE-2016-7965 [MEDIUM] CVE-2016-7965: dokuwiki - DokuWiki 2016-06-26a and older uses $_SERVER[HTTP_HOST] instead of the baseurl s...
DokuWiki 2016-06-26a and older uses $_SERVER[HTTP_HOST] instead of the baseurl setting as part of the password-reset URL. This can lead to phishing attacks. (A remote unauthenticated attacker can change the URL's hostname via the HTTP Host header.) The vulnerability can be triggered only if the Host header is not part of the web server routing process (e.g., if sev
debian
CVE-2014-8762P4MEDIUMCVSS 5.0fixed in dokuwiki 0.0.20140505.a+dfsg-1 (bookworm)2014
CVE-2014-8762 [MEDIUM] CVE-2014-8762: dokuwiki - The ajax_mediadiff function in DokuWiki before 2014-05-05a allows remote attacke...
The ajax_mediadiff function in DokuWiki before 2014-05-05a allows remote attackers to access arbitrary images via a crafted namespace in the ns parameter.
Scope: local
bookworm: resolved (fixed in 0.0.20140505.a+dfsg-1)
bullseye: resolved (fixed in 0.0.20140505.a+dfsg-1)
forky: resolved (fixed in 0.0.20140505.a+dfsg-1)
sid: resolved (fixed in 0.0.20140505.a+dfsg-1)
debian
CVE-2008-5186P4LOWCVSS 7.5fixed in dokuwiki 0.0.20080505-3.1 (bookworm)2008
CVE-2008-5186 [HIGH] CVE-2008-5186: dokuwiki - The set_language_path function in geshi.php in Generic Syntax Highlighter (GeSHi...
The set_language_path function in geshi.php in Generic Syntax Highlighter (GeSHi) before 1.0.8.1 might allow remote attackers to conduct file inclusion attacks via crafted inputs that influence the default language path ($path variable). NOTE: this issue has been disputed by a vendor, stating that only a static value is used, so this is not a vulnerability in GeSHi.
debian
CVE-2014-8761P4MEDIUMCVSS 5.0fixed in dokuwiki 0.0.20140505.a+dfsg-1 (bookworm)2014
CVE-2014-8761 [MEDIUM] CVE-2014-8761: dokuwiki - inc/template.php in DokuWiki before 2014-05-05a only checks for access to the ro...
inc/template.php in DokuWiki before 2014-05-05a only checks for access to the root namespace, which allows remote attackers to access arbitrary images via a media file details ajax call.
Scope: local
bookworm: resolved (fixed in 0.0.20140505.a+dfsg-1)
bullseye: resolved (fixed in 0.0.20140505.a+dfsg-1)
forky: resolved (fixed in 0.0.20140505.a+dfsg-1)
sid: resolved
debian
CVE-2010-0289P4LOWCVSS 6.8fixed in dokuwiki 0.0.20090214b-3.1 (bookworm)2010
CVE-2010-0289 [MEDIUM] CVE-2010-0289: dokuwiki - Multiple cross-site request forgery (CSRF) vulnerabilities in the ACL Manager pl...
Multiple cross-site request forgery (CSRF) vulnerabilities in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25c allow remote attackers to hijack the authentication of administrators for requests that modify access control rules, and other unspecified requests, via unknown vectors.
Scope: local
bookworm: resolved (fixed in 0.0.20090214b-3.
debian
CVE-2012-2128P4LOWCVSS 6.8fixed in dokuwiki 0.0.20120125a-1 (bookworm)2012
CVE-2012-2128 [MEDIUM] CVE-2012-2128: dokuwiki - Cross-site request forgery (CSRF) vulnerability in doku.php in DokuWiki 2012-01-...
Cross-site request forgery (CSRF) vulnerability in doku.php in DokuWiki 2012-01-25 Angua allows remote attackers to hijack the authentication of administrators for requests that add arbitrary users. NOTE: this issue has been disputed by the vendor, who states that it is resultant from CVE-2012-2129: "the exploit code simply uses the XSS hole to extract a valid CSRF
debian
1 / 2Next →