Gollum Project develops a lightweight wiki engine and library for Git-backed content management, with vulnerabilities clustering around its web interface and authentication handling. The durable signal centers on information-disclosure and access-control weaknesses, alongside cross-site scripting issues typical of wiki and user-generated-content platforms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gollum Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-9489HIGH The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string "master" is in any of the wiki docum | Oct 17, 2017 | 8.8 | 25 | NO | NO |
CVE-2020-35305MEDIUM Cross site scripting (XSS) in gollum 5.0 to 5.1.2 via the filename parameter to the 'New Page' dialog. | Jul 15, 2022 | 6.1 | 24 | NO | NO |
CVE-2015-7314MEDIUM The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. | Oct 6, 2015 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gollum Project.
Media articles that mention a CVE ID that affects a product developed by Gollum Project — matched by CVE ID, not by vendor name.