Vulnerabilities
Last updated 2 hours ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
YesWiki has Multiple Reflected Cross-site Scripting Vulnerabilities | Medium Risk 6.0 | 6 months ago | 6 hours ago |
|
|
YesWiki: Unauthenticated SQL Injection | Critical 9.8 | 4 months ago | 23 days ago |
|
|
YesWiki Vulnerable to Unauthenticated Reflected Cross-site Scripting | High Risk 7.6 | 1 year ago | 23 days ago |
|
|
Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting | Medium Risk 5.3 | 1 year ago | 23 days ago |
|
|
YesWiki Stored XSS Vulnerability in Comments | Low Risk 3.0 | 1 year ago | 23 days ago |
|
|
YesWiki Remote Code Execution via Arbitrary PHP File Write and Execution | High Risk 8.0 | 1 year ago | 23 days ago |
|
|
Yeswiki Vulnerable to Authenticated Reflected Cross-site Scripting | Low Risk 3.8 | 1 year ago | 23 days ago |
|
|
Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting | Medium Risk 5.3 | 1 year ago | 23 days ago |
|
|
Authenticated Stored XSS in YesWiki | High Risk 7.6 | 1 year ago | 23 days ago |
|
|
YesWiki Vulnerable to Unauthenticated Site Backup Creation and Download | Critical 10.0 | 1 year ago | 23 days ago |
|
|
YesWiki has Authenticated SQL Injection via ReactionManager | High Risk 8.8 | 2 months ago | 2 months ago |
|
|
YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`) | High Risk 8.3 | 2 months ago | 2 months ago |
|
|
YesWiki has stored XSS in Bazar form-field templates via unescaped field.label / field.hint (|raw('html')) | Medium Risk 5.5 | 2 months ago | 2 months ago |
|
|
YesWiki Vulnerable to Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php` | Medium Risk 6.1 | 2 months ago | 2 months ago |
|
|
YesWiki Vulnerable to Authenticated PHP Object Injection in BazarImportAction via unserialize | Critical 9.5 | 2 months ago | 2 months ago |
|
|
YesWiki: SQL Injection possible through public Bazar entry-listing APIs via numeric `query`/`queries` filters | High Risk 7.5 | 2 months ago | 2 months ago |
|
|
YesWiki Vulnerable to Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes | Medium Risk 6.1 | 2 months ago | 2 months ago |
|
|
YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service | Critical 9.8 | 2 months ago | 2 months ago |
|
|
YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates | High Risk 8.0 | 2 months ago | 2 months ago |
|
|
YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action | Critical 9.1 | 2 months ago | 2 months ago |
|
|
YesWiki: SQL injection via the `recentchanges` action `period` argument leads to arbitrary DB read | Medium Risk 6.5 | 2 months ago | 2 months ago |
|
|
YesWiki has Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId` | High Risk 8.3 | 2 months ago | 2 months ago |
|
|
YesWiki Vulnerable to Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)` | High Risk 8.2 | 2 months ago | 2 months ago |
|
|
YesWiki vulnerable to authenticated SQL Injection via id_fiche in EntryManager::formatDataBeforeSave() | High Risk 8.8 | 5 months ago | 4 months ago |
|
|
YesWiki has Persistent Blind XSS at "/?BazaR&vue=consulter" | High Risk 8.0 | 6 months ago | 5 months ago |
|
|
YesWiki Cross Site Scripting vulnerability | Medium Risk 6.1 | 1 year ago | 1 year ago |
|
|
Yeswiki Path Traversal vulnerability allows arbitrary read of files | High Risk 8.6 | 1 year ago | 1 year ago |
|
|
Authenticated arbitrary file deletion in YesWiki | High Risk 7.1 | 1 year ago | 1 year ago |
|
|
Unauthenticated DOM Based XSS in YesWiki | High Risk 7.6 | 1 year ago | 1 year ago |
|
|
YesWiki Uses a Broken or Risky Cryptographic Algorithm | Critical 9.9 | 1 year ago | 1 year ago |
|
|
SQL Injection in Yeswiki | High Risk 7.5 | 4 years ago | 2 years ago |
Page 1