Moinmo maintains MoinMoin, a widely deployed wiki engine that attracts a disproportionate vulnerability footprint relative to its product count, reflecting its integration into many collaborative platforms and knowledge-management systems. The vendor's disclosures center on application-layer input-handling and access-control weaknesses, particularly cross-site scripting, path traversal, information exposure, and authorization gaps, which are characteristic of web-facing systems that accept and render user content. A moderate share of the vendor's vulnerabilities acquire public exploit tooling, consistent with the straightforward nature of many web application flaws and the engine's open-source visibility. Defenders should treat MoinMoin instances as requiring regular patching, especially where they face untrusted networks, and should review configurations for access controls and input filtering; live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Moinmo over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-6081MEDIUM Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remo | Jan 3, 2013 | 6.0 | 57 | NO | YES |
CVE-2012-6495MEDIUM Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote au | Jan 3, 2013 | 6.0 | 38 | NO | YES |
CVE-2020-25074CRITICAL The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload attachments to the wiki can use | Nov 10, 2020 | 9.8 | 30 | NO | NO |
CVE-2012-6080MEDIUM Directory traversal vulnerability in the _do_attachment_move function in the AttachFile action (action/AttachFile.py) in MoinMoin 1.9.3 through 1.9.5 allows remote attackers to ove | Jan 3, 2013 | 6.4 | 23 | NO | NO |
CVE-2009-4762HIGH MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchical ACLs, which allows remote attackers t | Mar 29, 2010 | 7.5 | 23 | NO | NO |
CVE-2010-0717HIGH The default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does not prevent unsafe package actions, which has unspecified impact and attack vectors. | Feb 26, 2010 | 7.5 | 22 | NO | NO |
CVE-2010-0669HIGH MoinMoin before 1.8.7 and 1.9.x before 1.9.2 does not properly sanitize user profiles, which has unspecified impact and attack vectors. | Feb 26, 2010 | 7.5 | 22 | NO | NO |
CVE-2010-0668MEDIUM Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors, related to configurations that have a n | Feb 26, 2010 | 6.8 | 22 | NO | NO |
CVE-2012-4404MEDIUM security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote a | Sep 10, 2012 | 6.0 | 21 | NO | NO |
CVE-2017-5934MEDIUM Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified | Oct 15, 2018 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Moinmo.
Media articles that mention a CVE ID that affects a product developed by Moinmo — matched by CVE ID, not by vendor name.