Moinmoin
Vendor:
First CVE: Mar 30, 2009 · Active for 17 years
26
Total CVEs
More Total CVEs than 95% of tracked products
2.9
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Moinmoin over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 30, 2009
17 years ago
Most Recent CVE
Nov 11, 2020
2,081 days ago
CVE Severity & Scoring
Moinmoin26 CVEs
77%
12%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (23.1%)
Unknown20 (76.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (23.1%)
High0 (0.0%)
Unknown20 (76.9%)
User Interaction
None1 (3.8%)
Unknown20 (76.9%)
Required5 (19.2%)
Privileges Required
Low1 (3.8%)
High0 (0.0%)
None5 (19.2%)
Unknown20 (76.9%)
Top CVEs
Signals from CVEs in this product scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-6081MEDIUM Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remo | Jan 3, 2013 | 6.0 | 57 | NO | YES |
CVE-2012-6495MEDIUM Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote au | Jan 3, 2013 | 6.0 | 38 | NO | YES |
CVE-2020-25074CRITICAL The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload attachments to the wiki can use | Nov 10, 2020 | 9.8 | 30 | NO | NO |
CVE-2012-6080MEDIUM Directory traversal vulnerability in the _do_attachment_move function in the AttachFile action (action/AttachFile.py) in MoinMoin 1.9.3 through 1.9.5 allows remote attackers to ove | Jan 3, 2013 | 6.4 | 23 | NO | NO |
CVE-2009-4762HIGH MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchical ACLs, which allows remote attackers t | Mar 29, 2010 | 7.5 | 23 | NO | NO |
CVE-2010-0717HIGH The default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does not prevent unsafe package actions, which has unspecified impact and attack vectors. | Feb 26, 2010 | 7.5 | 22 | NO | NO |
CVE-2010-0669HIGH MoinMoin before 1.8.7 and 1.9.x before 1.9.2 does not properly sanitize user profiles, which has unspecified impact and attack vectors. | Feb 26, 2010 | 7.5 | 22 | NO | NO |
CVE-2010-0668MEDIUM Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors, related to configurations that have a n | Feb 26, 2010 | 6.8 | 22 | NO | NO |
CVE-2012-4404MEDIUM security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote a | Sep 10, 2012 | 6.0 | 21 | NO | NO |
CVE-2017-5934MEDIUM Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified | Oct 15, 2018 | 6.1 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (26 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.8% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
7.7% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (26 CVEs).
Media Mentions
Signals from CVEs in this product scope (26 CVEs).
Top CNAs Publishing CVEs For Moinmoin
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.9.8 | 2 | 6.1 | 1.2% | 0 | 0 |
| 1.9.5 | 2 | 5.3 | 3.1% | 0 | 0 |
| 1.9.4 | 4 | 6.1 | 13.8% | 0 | 2 |
| 1.9.3 | 4 | 6.1 | 13.8% | 0 | 2 |
| 1.9.2 | 7 | 4.9 | 8.7% | 0 | 2 |
| 1.9.1 | 9 | 5.3 | 7.3% | 0 | 2 |
| 1.9.0 | 10 | 5.3 | 6.7% | 0 | 2 |
| 1.8.8 | 3 | 4.9 | 17.2% | 0 | 2 |
| 1.8.7 | 5 | 4.5 | 11.3% | 0 | 2 |
| 1.8.6 | 5 | 5.1 | 11.3% | 0 | 2 |
| 1.8.4 | 7 | 5.8 | 8.6% | 0 | 2 |
| 1.8.3 | 7 | 5.8 | 8.6% | 0 | 2 |
| 1.8.2 | 8 | 6.0 | 7.9% | 0 | 2 |
| 1.8.1 | 8 | 6.0 | 7.9% | 0 | 2 |
| 1.8.0 | 8 | 6.0 | 7.9% | 0 | 2 |
| 1.7.3 | 6 | 6.1 | 9.6% | 0 | 2 |
| 1.7.2 | 9 | 5.8 | 7.3% | 0 | 2 |
| 1.7.1 | 10 | 5.8 | 6.8% | 0 | 2 |
| 1.7.0 | 10 | 5.7 | 7.6% | 0 | 2 |
| 1.6.4 | 8 | 5.6 | 7.9% | 0 | 2 |