Vulnerabilities
Vulnerable Software
Foswiki:  >> Foswiki  >> 1.1.2  Security Vulnerabilities
An issue in the SpreadSheetPlugin component of Foswiki v2.1.7 and below allows attackers to execute a directory traversal.
CVSS Score
7.5
EPSS Score
0.005
Published
2023-08-08
Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro.
CVSS Score
9.8
EPSS Score
0.041
Published
2019-11-01
The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to cause a denial of service (memory consumption) via a large integer in a %MAKETEXT% macro.
CVSS Score
5.0
EPSS Score
0.733
Published
2013-01-04
Multiple cross-site scripting (XSS) vulnerabilities in UI/Register.pm in Foswiki before 1.1.5 allow remote authenticated users with CHANGE privileges to inject arbitrary web script or HTML via the (1) text, (2) FirstName, (3) LastName, (4) OrganisationName, (5) OrganisationUrl, (6) Profession, (7) Country, (8) State, (9) Address, (10) Location, (11) Telephone, (12) VoIP, (13) InstantMessagingIM, (14) Email, (15) HomePage, or (16) Comment parameter. NOTE: some of these details are obtained from third party information.
CVSS Score
2.1
EPSS Score
0.003
Published
2012-02-08
Multiple cross-site scripting (XSS) vulnerabilities in JumpBox before 1.1.2 for Foswiki Wiki System allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS Score
4.3
EPSS Score
0.003
Published
2010-05-07


Contact Us

Shodan ® - All rights reserved