Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.4% | — | Andreas Gohr Dokuwiki | 13/7/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the tpl_mediaFileList function in inc/template.php in DokuWiki before 2012-01-25b allows remote attackers to inject arbitrary web script or HTML via the ns parameter in a medialist action to lib/exe/ajax.php. | |
| Modificada | Media (5) | 2.0% | — | Dokuwiki | 23/9/2011 | 16/6/2026 | DokuWiki 2009-12-25c allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lib/tpl/index.php and certain other files. | |
| Modificada | Media (4.3) | 1.7% | — | Dokuwiki | 14/7/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the RSS embedding feature in DokuWiki before 2011-05-25a Rincewind allows remote attackers to inject arbitrary web script or HTML via a link. | |
| Modificada | Media (6.8) | 1.8% | — | Dokuwiki | 15/2/2010 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25c allow remote attackers to hijack the authentication of administrators for requests that modify access control rules, and other unspecified requests, via unknown vectors. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Dokuwiki | 15/2/2010 | 16/6/2026 | A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to gain privileges and access closed wikis by editing current ACL statements, as demonstrated in the wild in January 2010. | |
| Modificada | Media (5) | 11% | 💥 Exploit | Dokuwiki | 15/2/2010 | 16/6/2026 | Directory traversal vulnerability in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to list the contents of arbitrary directories via a .. (dot dot) in the ns parameter. | |
| Modificada | Alta (9.3) | 23% | 💥 Exploit | Dokuwiki | 8/6/2009 | 16/6/2026 | inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. NOTE: PHP remote file inclusion is also possible in PHP 5 using ftp:// URLs. | |
| Modificada | Media (4.3) | 19% | — | Microsoft Internet ExplorerDokuwiki | 21/7/2007 | 16/6/2026 | Interpretation conflict between Microsoft Internet Explorer and DocuWiki before 2007-06-26b allows remote attackers to inject arbitrary JavaScript and conduct cross-site scripting (XSS) attacks when spellchecking UTF-8 encoded messages via the spell_utf8test function in lib/exe/spellcheck.php, which triggers HTML… | |
| Modificada | Media (4.3) | 1.4% | — | Andreas Gohr Dokuwiki | 29/1/2007 | 16/6/2026 | CRLF injection vulnerability in lib/exe/fetch.php in DokuWiki 2006-03-09e, and possibly earlier, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the media parameter. NOTE: this issue can be leveraged for XSS attacks. | |
| Modificada | Media (5) | 1.7% | — | Andreas Gohr Dokuwiki | 29/9/2006 | 16/6/2026 | lib/exec/fetch.php in DokuWiki before 2006-03-09e allows remote attackers to cause a denial of service (CPU consumption) via large w and h parameters, when resizing an image. | |
| Modificada | Alta (7.5) | 2.2% | — | Andreas Gohr Dokuwiki | 29/9/2006 | 16/6/2026 | lib/exec/fetch.php in DokuWiki before 2006-03-09e, when conf[imconvert] is configured to use ImageMagick, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) w and (2) h parameters, which are not filtered when invoking convert. | |
| Modificada | Alta (7.5) | 1.9% | — | Andreas Gohr Dokuwiki | 11/9/2006 | 16/6/2026 | Direct static code injection vulnerability in doku.php in DokuWiki before 2006-030-09c allows remote attackers to execute arbitrary PHP code via the X-FORWARDED-FOR HTTP header, which is stored in config.php. | |
| Modificada | Alta (7.5) | 1.9% | — | Andreas Gohr Dokuwiki | 11/9/2006 | 16/6/2026 | Unrestricted file upload vulnerability in lib/exe/media.php in DokuWiki before 2006-03-09c allows remote attackers to upload executable files into the data/media folder via unspecified vectors. | |
| Modificada | Media (5) | 1.7% | — | Andreas Gohr Dokuwiki | 11/9/2006 | 16/6/2026 | DokuWiki before 2006-03-09c enables the debug feature by default, which allows remote attackers to obtain sensitive information by calling doku.php with the X-DOKUWIKI-DO HTTP header set to "debug". | |
| Modificada | Media (4) | 1.1% | — | Andreas Gohr Dokuwiki | 12/6/2006 | 16/6/2026 | Unspecified vulnerability in the user profile change functionality in DokuWiki, when Access Control Lists are enabled, allows remote authenticated users to read unauthorized files via unknown attack vectors. | |
| Modificada | Alta (7.5) | 14% | — | Andreas Gohr Dokuwiki | 7/6/2006 | 16/6/2026 | The spellchecker (spellcheck.php) in DokuWiki 2006/06/04 and earlier allows remote attackers to insert and execute arbitrary PHP code via "complex curly syntax" that is inserted into a regular expression that is processed by preg_replace with the /e (executable) modifier. | |
| Modificada | Media (4.3) | 1.2% | — | Andreas Gohr Dokuwiki | 12/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the mediamanager module in DokuWiki before 2006-03-05 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors relating to "handling EXIF data." | |
| Modificada | Alta (7.5) | 2.8% | — | Andreas Gohr Dokuwiki | 31/12/2004 | 16/6/2026 | DokuWiki before 2004-10-19, when used on a web server that permits execution based on file extension, allows remote attackers to execute arbitrary code by uploading a file with an appropriate extension such as ".php" or ".cgi". | |
| Modificada | Alta (7.5) | 1.6% | — | Andreas Gohr Dokuwiki | 31/12/2004 | 16/6/2026 | DokuWiki before 2004-10-19 allows remote attackers to access administrative functionality including (1) Mediaselectiondialog, (2) Recent changes, (3) feed, and (4) search, possibly due to the lack of ACL checks. |