Foswiki is a lightweight, open-source wiki collaboration platform deployed across organizations for knowledge management and team documentation, presenting a narrowly scoped but structurally exposed surface. The vendor's vulnerabilities skew toward serious outcomes, frequently acquire public exploit code, and recur through weakness classes endemic to server-side wiki systems: path traversal, cross-site scripting, cross-site request forgery, information exposure, and access-control flaws that often arise from the platform's flexible templating and plugin architecture. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Foswiki over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-6330MEDIUM The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to cause a denial of service (memory consump | Jan 4, 2013 | 5.0 | 47 | NO | YES |
CVE-2013-1666CRITICAL Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro. | Nov 1, 2019 | 9.8 | 31 | NO | NO |
CVE-2023-33756HIGH An issue in the SpreadSheetPlugin component of Foswiki v2.1.7 and below allows attackers to execute a directory traversal. | Aug 8, 2023 | 7.5 | 22 | NO | NO |
CVE-2026-2861MEDIUM A vulnerability was detected in Foswiki up to 2.1.10. The affected element is an unknown function of the component Changes/Viewfile/Oops. The manipulation results in information di | Feb 21, 2026 | 5.3 | 21 | NO | NO |
CVE-2023-24698HIGH Insufficient parameter validation in the Foswiki::Sandbox component of Foswiki v2.1.7 and below allows attackers to perform a directory traversal via supplying a crafted web reques | Aug 8, 2023 | 7.5 | 21 | NO | NO |
CVE-2010-4215MEDIUM UI/Manage.pm in Foswiki 1.1.0 and 1.1.1 allows remote authenticated users to gain privileges by modifying the GROUP and ALLOWTOPICCHANGE preferences in the topic preferences for Ma | Nov 17, 2010 | 6.5 | 21 | NO | NO |
CVE-2009-1434MEDIUM Cross-site request forgery (CSRF) vulnerability in Foswiki before 1.0.5 allows remote attackers to hijack the authentication of arbitrary users for requests that modify pages, chan | Apr 30, 2009 | 6.8 | 19 | NO | NO |
CVE-2009-4853MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in JumpBox before 1.1.2 for Foswiki Wiki System allow remote attackers to inject arbitrary web script or HTML via unspecified ve | May 7, 2010 | 4.3 | 16 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in UI/Register.pm in Foswiki before 1.1.5 allow remote authenticated users with CHANGE privileges to inject arbitrary web script | Feb 8, 2012 | 2.1 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Foswiki.
Media articles that mention a CVE ID that affects a product developed by Foswiki — matched by CVE ID, not by vendor name.