Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Foswiki

First CVE: Apr 30, 2009Active for: 17 yearsTotal CVEs: 9

Foswiki is a lightweight, open-source wiki collaboration platform deployed across organizations for knowledge management and team documentation, presenting a narrowly scoped but structurally exposed surface. The vendor's vulnerabilities skew toward serious outcomes, frequently acquire public exploit code, and recur through weakness classes endemic to server-side wiki systems: path traversal, cross-site scripting, cross-site request forgery, information exposure, and access-control flaws that often arise from the platform's flexible templating and plugin architecture. Current severity, exploitation, and exposure metrics are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Foswiki over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 30, 2009
17 years ago
Most Recent CVE
Feb 21, 2026
153 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-6330MEDIUM
The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to cause a denial of service (memory consump
Jan 4, 20135.047NOYES
CVE-2013-1666CRITICAL
Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro.
Nov 1, 20199.831NONO
CVE-2023-33756HIGH
An issue in the SpreadSheetPlugin component of Foswiki v2.1.7 and below allows attackers to execute a directory traversal.
Aug 8, 20237.522NONO
CVE-2026-2861MEDIUM
A vulnerability was detected in Foswiki up to 2.1.10. The affected element is an unknown function of the component Changes/Viewfile/Oops. The manipulation results in information di
Feb 21, 20265.321NONO
CVE-2023-24698HIGH
Insufficient parameter validation in the Foswiki::Sandbox component of Foswiki v2.1.7 and below allows attackers to perform a directory traversal via supplying a crafted web reques
Aug 8, 20237.521NONO
CVE-2010-4215MEDIUM
UI/Manage.pm in Foswiki 1.1.0 and 1.1.1 allows remote authenticated users to gain privileges by modifying the GROUP and ALLOWTOPICCHANGE preferences in the topic preferences for Ma
Nov 17, 20106.521NONO
CVE-2009-1434MEDIUM
Cross-site request forgery (CSRF) vulnerability in Foswiki before 1.0.5 allows remote attackers to hijack the authentication of arbitrary users for requests that modify pages, chan
Apr 30, 20096.819NONO
CVE-2009-4853MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in JumpBox before 1.1.2 for Foswiki Wiki System allow remote attackers to inject arbitrary web script or HTML via unspecified ve
May 7, 20104.316NONO
CVE-2012-1004LOW
Multiple cross-site scripting (XSS) vulnerabilities in UI/Register.pm in Foswiki before 1.1.5 allow remote authenticated users with CHANGE privileges to inject arbitrary web script
Feb 8, 20122.115NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
11%
56%
22%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (44.4%)
Unknown5 (55.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (44.4%)
High0 (0.0%)
Unknown5 (55.6%)
User Interaction
None4 (44.4%)
Unknown5 (55.6%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (44.4%)
Unknown5 (55.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
11.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Foswiki.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Foswiki — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Foswiki's Products

View all 2 CNAs →

Top CWEs