Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Moinmo

First CVE: Mar 30, 2009Active for: 17 yearsTotal CVEs: 26
36.1
VTI Score
Medium

Moinmo maintains MoinMoin, a widely deployed wiki engine that attracts a disproportionate vulnerability footprint relative to its product count, reflecting its integration into many collaborative platforms and knowledge-management systems. The vendor's disclosures center on application-layer input-handling and access-control weaknesses, particularly cross-site scripting, path traversal, information exposure, and authorization gaps, which are characteristic of web-facing systems that accept and render user content. A moderate share of the vendor's vulnerabilities acquire public exploit tooling, consistent with the straightforward nature of many web application flaws and the engine's open-source visibility. Defenders should treat MoinMoin instances as requiring regular patching, especially where they face untrusted networks, and should review configurations for access controls and input filtering; live severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
2.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
5.7
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Moinmo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 30, 2009
17 years ago
Most Recent CVE
Nov 11, 2020
2,081 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-6081MEDIUM
Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remo
Jan 3, 20136.057NOYES
CVE-2012-6495MEDIUM
Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote au
Jan 3, 20136.038NOYES
CVE-2020-25074CRITICAL
The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload attachments to the wiki can use
Nov 10, 20209.830NONO
CVE-2012-6080MEDIUM
Directory traversal vulnerability in the _do_attachment_move function in the AttachFile action (action/AttachFile.py) in MoinMoin 1.9.3 through 1.9.5 allows remote attackers to ove
Jan 3, 20136.423NONO
CVE-2009-4762HIGH
MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchical ACLs, which allows remote attackers t
Mar 29, 20107.523NONO
CVE-2010-0717HIGH
The default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does not prevent unsafe package actions, which has unspecified impact and attack vectors.
Feb 26, 20107.522NONO
CVE-2010-0669HIGH
MoinMoin before 1.8.7 and 1.9.x before 1.9.2 does not properly sanitize user profiles, which has unspecified impact and attack vectors.
Feb 26, 20107.522NONO
CVE-2010-0668MEDIUM
Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors, related to configurations that have a n
Feb 26, 20106.822NONO
CVE-2012-4404MEDIUM
security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote a
Sep 10, 20126.021NONO
CVE-2017-5934MEDIUM
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified
Oct 15, 20186.119NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
77%
12%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (23.1%)
Unknown20 (76.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (23.1%)
High0 (0.0%)
Unknown20 (76.9%)
User Interaction
None1 (3.8%)
Unknown20 (76.9%)
Required5 (19.2%)
Privileges Required
Low1 (3.8%)
High0 (0.0%)
None5 (19.2%)
Unknown20 (76.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.8% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
7.7% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Moinmo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Moinmo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Moinmo's Products

View all 4 CNAs →

Top CWEs