cbcvebase.

Debian Dokuwiki vulnerabilities

34 known vulnerabilities affecting debian/dokuwiki.

Total CVEs
34
CISA KEV
0
Public exploits
5
Exploited in wild
1
Severity breakdown
HIGH2MEDIUM18LOW14

Vulnerabilities

Page 2 of 2
CVE-2017-12980P4MEDIUMCVSS 6.1fixed in dokuwiki 0.0.20180422.a-1 (bookworm)2017
CVE-2017-12980 [MEDIUM] CVE-2017-12980: dokuwiki - DokuWiki through 2017-02-19c has stored XSS when rendering a malicious RSS or At... DokuWiki through 2017-02-19c has stored XSS when rendering a malicious RSS or Atom feed, in /inc/parser/xhtml.php. An attacker can create or edit a wiki that uses RSS or Atom data from an attacker-controlled server to trigger JavaScript execution. The JavaScript can be in an author field, as demonstrated by the dc:creator element. Scope: local bookworm: resolved
debian
CVE-2017-12979P4MEDIUMCVSS 6.1fixed in dokuwiki 0.0.20180422.a-1 (bookworm)2017
CVE-2017-12979 [MEDIUM] CVE-2017-12979: dokuwiki - DokuWiki through 2017-02-19c has stored XSS when rendering a malicious language ... DokuWiki through 2017-02-19c has stored XSS when rendering a malicious language name in a code element, in /inc/parser/xhtml.php. An attacker can create or edit a wiki with this element to trigger JavaScript execution. Scope: local bookworm: resolved (fixed in 0.0.20180422.a-1) bullseye: resolved (fixed in 0.0.20180422.a-1) forky: resolved (fixed in 0.0.20180422.
debian
CVE-2014-9253P4MEDIUMCVSS 4.3fixed in dokuwiki 0.0.20140929.d-1 (bookworm)2014
CVE-2014-9253 [MEDIUM] CVE-2014-9253: dokuwiki - The default file type whitelist configuration in conf/mime.conf in the Media Man... The default file type whitelist configuration in conf/mime.conf in the Media Manager in DokuWiki before 2014-09-29b allows remote attackers to execute arbitrary web script or HTML by uploading an SWF file, then accessing it via the media parameter to lib/exe/fetch.php. Scope: local bookworm: resolved (fixed in 0.0.20140929.d-1) bullseye: resolved (fixed in 0.0.2014
debian
CVE-2022-28919P4MEDIUMCVSS 6.1fixed in dokuwiki 0.0.20220731.a-1 (bookworm)2022
CVE-2022-28919 [MEDIUM] CVE-2022-28919: dokuwiki - HTMLCreator release_stable_2020-07-29 was discovered to contain a cross-site scr... HTMLCreator release_stable_2020-07-29 was discovered to contain a cross-site scripting (XSS) vulnerability via the function _generateFilename. Scope: local bookworm: resolved (fixed in 0.0.20220731.a-1) bullseye: open forky: resolved (fixed in 0.0.20220731.a-1) sid: resolved (fixed in 0.0.20220731.a-1) trixie: resolved (fixed in 0.0.20220731.a-1)
debian
CVE-2023-34408P4MEDIUMCVSS 5.4fixed in dokuwiki 0.0.20220731.a-2 (bookworm)2023
CVE-2023-34408 [MEDIUM] CVE-2023-34408: dokuwiki - DokuWiki before 2023-04-04a allows XSS via RSS titles. DokuWiki before 2023-04-04a allows XSS via RSS titles. Scope: local bookworm: resolved (fixed in 0.0.20220731.a-2) bullseye: open forky: resolved (fixed in 0.0.20220731.a-2) sid: resolved (fixed in 0.0.20220731.a-2) trixie: resolved (fixed in 0.0.20220731.a-2)
debian
CVE-2012-2129P4LOWCVSS 4.3fixed in dokuwiki 0.0.20120125a-1 (bookworm)2012
CVE-2012-2129 [MEDIUM] CVE-2012-2129: dokuwiki - Cross-site scripting (XSS) vulnerability in doku.php in DokuWiki 2012-01-25 Angu... Cross-site scripting (XSS) vulnerability in doku.php in DokuWiki 2012-01-25 Angua allows remote attackers to inject arbitrary web script or HTML via the target parameter in an edit action. Scope: local bookworm: resolved (fixed in 0.0.20120125a-1) bullseye: resolved (fixed in 0.0.20120125a-1) forky: resolved (fixed in 0.0.20120125a-1) sid: resolved (fixed in 0.0.20
debian
CVE-2011-2510P4LOWCVSS 4.3fixed in dokuwiki 0.0.20110525a-1 (bookworm)2011
CVE-2011-2510 [MEDIUM] CVE-2011-2510: dokuwiki - Cross-site scripting (XSS) vulnerability in the RSS embedding feature in DokuWik... Cross-site scripting (XSS) vulnerability in the RSS embedding feature in DokuWiki before 2011-05-25a Rincewind allows remote attackers to inject arbitrary web script or HTML via a link. Scope: local bookworm: resolved (fixed in 0.0.20110525a-1) bullseye: resolved (fixed in 0.0.20110525a-1) forky: resolved (fixed in 0.0.20110525a-1) sid: resolved (fixed in 0.0.20110
debian
CVE-2006-4679P4LOWCVSS 5.0fixed in dokuwiki 0.0.20060309-5.1 (bookworm)2006
CVE-2006-4679 [MEDIUM] CVE-2006-4679: dokuwiki - DokuWiki before 2006-03-09c enables the debug feature by default, which allows r... DokuWiki before 2006-03-09c enables the debug feature by default, which allows remote attackers to obtain sensitive information by calling doku.php with the X-DOKUWIKI-DO HTTP header set to "debug". Scope: local bookworm: resolved (fixed in 0.0.20060309-5.1) bullseye: resolved (fixed in 0.0.20060309-5.1) forky: resolved (fixed in 0.0.20060309-5.1) sid: resolved (fi
debian
CVE-2006-5098P4MEDIUMCVSS 5.0fixed in dokuwiki 0.0.20060309-5.2 (bookworm)2006
CVE-2006-5098 [MEDIUM] CVE-2006-5098: dokuwiki - lib/exec/fetch.php in DokuWiki before 2006-03-09e allows remote attackers to cau... lib/exec/fetch.php in DokuWiki before 2006-03-09e allows remote attackers to cause a denial of service (CPU consumption) via large w and h parameters, when resizing an image. Scope: local bookworm: resolved (fixed in 0.0.20060309-5.2) bullseye: resolved (fixed in 0.0.20060309-5.2) forky: resolved (fixed in 0.0.20060309-5.2) sid: resolved (fixed in 0.0.20060309-5.2)
debian
CVE-2012-0283P4LOWCVSS 4.3fixed in dokuwiki 0.0.20120125b-1 (bookworm)2012
CVE-2012-0283 [MEDIUM] CVE-2012-0283: dokuwiki - Cross-site scripting (XSS) vulnerability in the tpl_mediaFileList function in in... Cross-site scripting (XSS) vulnerability in the tpl_mediaFileList function in inc/template.php in DokuWiki before 2012-01-25b allows remote attackers to inject arbitrary web script or HTML via the ns parameter in a medialist action to lib/exe/ajax.php. Scope: local bookworm: resolved (fixed in 0.0.20120125b-1) bullseye: resolved (fixed in 0.0.20120125b-1) forky: re
debian
CVE-2006-6965P4LOWCVSS 4.3fixed in dokuwiki 0.0.20061106-1 (bookworm)2006
CVE-2006-6965 [MEDIUM] CVE-2006-6965: dokuwiki - CRLF injection vulnerability in lib/exe/fetch.php in DokuWiki 2006-03-09e, and p... CRLF injection vulnerability in lib/exe/fetch.php in DokuWiki 2006-03-09e, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the media parameter. NOTE: this issue can be leveraged for XSS attacks. Scope: local bookworm: resolved (fixed in 0.0.20061106-1) bullseye: resolve
debian
CVE-2006-1165P4MEDIUMCVSS 4.3fixed in dokuwiki 0.0.20060309-3 (bookworm)2006
CVE-2006-1165 [MEDIUM] CVE-2006-1165: dokuwiki - Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki ... Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors relating to "handling EXIF data." Scope: local bookworm: resolved (fixed in 0.0.20060309-3) bullseye: resolved (fixed in 0.0.20060309-3) forky: resolved (fixed in 0.0.20060309-3)
debian
CVE-2006-2945P4LOWCVSS 4.0fixed in dokuwiki 0.0.20060309-4 (bookworm)2006
CVE-2006-2945 [MEDIUM] CVE-2006-2945: dokuwiki - Unspecified vulnerability in the user profile change functionality in DokuWiki, ... Unspecified vulnerability in the user profile change functionality in DokuWiki, when Access Control Lists are enabled, allows remote authenticated users to read unauthorized files via unknown attack vectors. Scope: local bookworm: resolved (fixed in 0.0.20060309-4) bullseye: resolved (fixed in 0.0.20060309-4) forky: resolved (fixed in 0.0.20060309-4) sid: resolved
debian
CVE-2012-3354P4LOWCVSS 4.3fixed in dokuwiki 0.0.20130510a-1 (bookworm)2012
CVE-2012-3354 [MEDIUM] CVE-2012-3354: dokuwiki - doku.php in DokuWiki, as used in Fedora 16, 17, and 18, when certain PHP error l... doku.php in DokuWiki, as used in Fedora 16, 17, and 18, when certain PHP error levels are set, allows remote attackers to obtain sensitive information via the prefix parameter, which reveals the installation path in an error message. Scope: local bookworm: resolved (fixed in 0.0.20130510a-1) bullseye: resolved (fixed in 0.0.20130510a-1) forky: resolved (fixed in 0.
debian
Debian Dokuwiki vulnerabilities | cvebase