Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ikiwiki

First CVE: Feb 19, 2008Active for: 18 yearsTotal CVEs: 18
22.0
VTI Score
Low

Ikiwiki is a lightweight wiki engine and static-site generator widely embedded in documentation and collaborative publishing workflows, where its vulnerability footprint concentrates in a single focused product. The recurring exposure reflects the challenges inherent to web-facing content management: cross-site scripting and input-neutralization issues in page rendering, access control and authentication gaps in user and permission management, and link-following flaws that can lead to unintended file access. A meaningful share of vulnerabilities affecting this vendor reach serious severity; defenders should prioritize updates for instances exposed to untrusted input or hosting sensitive collaborative content, while live counts and severity details are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 27% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ikiwiki over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 19, 2008
18 years ago
Most Recent CVE
Nov 21, 2019
2,437 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-0356CRITICAL
A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker to bypass authentication via re
Apr 13, 20189.831NONO
CVE-2011-1408HIGH
ikiwiki before 3.20110608 allows remote attackers to hijack root's tty and run symlink attacks.
Oct 29, 20198.227NONO
CVE-2016-10026HIGH
ikiwiki 3.20161219 does not properly check if a revision changes the access permissions for a page on sites with the git and recentchanges plugins and the CGI interface enabled, wh
Feb 13, 20177.526NONO
CVE-2010-1673MEDIUM
A cross-site scripting (XSS) vulnerability in ikiwiki before 3.20101112 allows remote attackers to inject arbitrary web script or HTML via a comment.
Oct 30, 20196.122NONO
CVE-2011-0428MEDIUM
Cross Site Scripting (XSS) in ikiwiki before 3.20110122 could allow remote attackers to insert arbitrary JavaScript due to insufficient checking in comments.
Oct 29, 20196.122NONO
CVE-2016-4561MEDIUM
Cross-site scripting (XSS) vulnerability in the cgierror function in CGI.pm in ikiwiki before 3.20160506 might allow remote attackers to inject arbitrary web script or HTML via uns
May 10, 20166.120NONO
CVE-2008-0169MEDIUM
Plugin/passwordauth.pm (aka the passwordauth plugin) in ikiwiki 1.34 through 2.47 allows remote attackers to bypass authentication, and login to any account for which an OpenID ide
Jun 3, 20086.820NONO
CVE-2019-9187HIGH
ikiwiki before 3.20170111.1 and 3.2018x and 3.2019x before 3.20190228 allows SSRF via the aggregate plugin. The impact also includes reading local files via file: URIs.
Jun 5, 20197.519NONO
CVE-2012-0220MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the meta plugin (Plugin/meta.pm) in ikiwiki before 3.20120516 allow remote attackers to inject arbitrary web script or HTML v
May 29, 20124.319NONO
CVE-2015-2793MEDIUM
Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150329 allows remote attackers to inject arbitrary web script or HTML via the openi
Nov 21, 20196.117NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
72%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (55.6%)
Unknown8 (44.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (55.6%)
High0 (0.0%)
Unknown8 (44.4%)
User Interaction
None6 (33.3%)
Unknown8 (44.4%)
Required4 (22.2%)
Privileges Required
Low1 (5.6%)
High0 (0.0%)
None9 (50.0%)
Unknown8 (44.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ikiwiki.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ikiwiki — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ikiwiki's Products

View all 2 CNAs →

Top CWEs