Ikiwiki is a lightweight wiki engine and static-site generator widely embedded in documentation and collaborative publishing workflows, where its vulnerability footprint concentrates in a single focused product. The recurring exposure reflects the challenges inherent to web-facing content management: cross-site scripting and input-neutralization issues in page rendering, access control and authentication gaps in user and permission management, and link-following flaws that can lead to unintended file access. A meaningful share of vulnerabilities affecting this vendor reach serious severity; defenders should prioritize updates for instances exposed to untrusted input or hosting sensitive collaborative content, while live counts and severity details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ikiwiki over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-0356CRITICAL A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via re | Apr 13, 2018 | 9.8 | 31 | NO | NO |
CVE-2011-1408HIGH ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks. | Oct 29, 2019 | 8.2 | 27 | NO | NO |
CVE-2016-10026HIGH ikiwiki 3.20161219 does not properly check if a revision changes the access permissions for a page on sites with the git and recentchanges plugins and the CGI interface enabled, wh | Feb 13, 2017 | 7.5 | 26 | NO | NO |
CVE-2010-1673MEDIUM A cross-site scripting (XSS) vulnerability in ikiwiki before 3.20101112 allows remote attackers to inject arbitrary web script or HTML via a comment. | Oct 30, 2019 | 6.1 | 22 | NO | NO |
CVE-2011-0428MEDIUM Cross Site Scripting (XSS) in ikiwiki before 3.20110122 could allow remote attackers to insert arbitrary JavaScript due to insufficient checking in comments. | Oct 29, 2019 | 6.1 | 22 | NO | NO |
CVE-2016-4561MEDIUM Cross-site scripting (XSS) vulnerability in the cgierror function in CGI.pm in ikiwiki before 3.20160506 might allow remote attackers to inject arbitrary web script or HTML via uns | May 10, 2016 | 6.1 | 20 | NO | NO |
CVE-2008-0169MEDIUM Plugin/passwordauth.pm (aka the passwordauth plugin) in ikiwiki 1.34 through 2.47 allows remote attackers to bypass authentication, and login to any account for which an OpenID ide | Jun 3, 2008 | 6.8 | 20 | NO | NO |
CVE-2019-9187HIGH ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact also includes reading local files via file: URIs. | Jun 5, 2019 | 7.5 | 19 | NO | NO |
CVE-2012-0220MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the meta plugin (Plugin/meta.pm) in ikiwiki before 3.20120516 allow remote attackers to inject arbitrary web script or HTML v | May 29, 2012 | 4.3 | 19 | NO | NO |
CVE-2015-2793MEDIUM Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150329 allows remote attackers to inject arbitrary web script or HTML via the openi | Nov 21, 2019 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ikiwiki.
Media articles that mention a CVE ID that affects a product developed by Ikiwiki — matched by CVE ID, not by vendor name.