Moinmoin

Vendor:

First CVE: Mar 30, 2009 · Active for 17 years

26
Total CVEs
More Total CVEs than 95% of tracked products
2.9
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Moinmoin over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 30, 2009
17 years ago
Most Recent CVE
Nov 11, 2020
2,081 days ago

CVE Severity & Scoring

Moinmoin26 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (23.1%)
Unknown20 (76.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (23.1%)
High0 (0.0%)
Unknown20 (76.9%)
User Interaction
None1 (3.8%)
Unknown20 (76.9%)
Required5 (19.2%)
Privileges Required
Low1 (3.8%)
High0 (0.0%)
None5 (19.2%)
Unknown20 (76.9%)

Top CVEs

Signals from CVEs in this product scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remo
Jan 3, 20136.057NOYES
Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote au
Jan 3, 20136.038NOYES
The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload attachments to the wiki can use
Nov 10, 20209.830NONO
Directory traversal vulnerability in the _do_attachment_move function in the AttachFile action (action/AttachFile.py) in MoinMoin 1.9.3 through 1.9.5 allows remote attackers to ove
Jan 3, 20136.423NONO
MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchical ACLs, which allows remote attackers t
Mar 29, 20107.523NONO
The default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does not prevent unsafe package actions, which has unspecified impact and attack vectors.
Feb 26, 20107.522NONO
MoinMoin before 1.8.7 and 1.9.x before 1.9.2 does not properly sanitize user profiles, which has unspecified impact and attack vectors.
Feb 26, 20107.522NONO
Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors, related to configurations that have a n
Feb 26, 20106.822NONO
security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote a
Sep 10, 20126.021NONO
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified
Oct 15, 20186.119NONO

Exploit Exposure

Signals from CVEs in this product scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.8% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
7.7% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (26 CVEs).

Media Mentions

Signals from CVEs in this product scope (26 CVEs).

Top CNAs Publishing CVEs For Moinmoin

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.9.826.11.2%00
1.9.525.33.1%00
1.9.446.113.8%02
1.9.346.113.8%02
1.9.274.98.7%02
1.9.195.37.3%02
1.9.0105.36.7%02
1.8.834.917.2%02
1.8.754.511.3%02
1.8.655.111.3%02
1.8.475.88.6%02
1.8.375.88.6%02
1.8.286.07.9%02
1.8.186.07.9%02
1.8.086.07.9%02
1.7.366.19.6%02
1.7.295.87.3%02
1.7.1105.86.8%02
1.7.0105.77.6%02
1.6.485.67.9%02