Moniwiki is a lightweight wiki engine with a narrowly scoped product line, presenting a modest attack surface centered on its core wiki platform. The observed weakness classes reflect generic categorization limitations rather than a clear structural vulnerability pattern, so defenders should consult live severity, exploitation, and exposure counts shown alongside this summary.
The number and severity of CVEs published that impact products developed by Moniwiki over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1545MEDIUM UploadFile.php in MoniWiki 1.0.9.2 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, such as .php.hwp, which allows remote attac | Dec 31, 2004 | 5.0 | 15 | NO | NO |
CVE-2004-1632MEDIUM Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki 1.0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the arguments to wiki.php. | Oct 25, 2004 | 4.3 | 14 | NO | NO |
Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki before 1.1.2-20060702 allows remote attackers to inject arbitrary Javascript via the URL, which is reflected back i | Jul 6, 2006 | 2.6 | 12 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Moniwiki.
Media articles that mention a CVE ID that affects a product developed by Moniwiki — matched by CVE ID, not by vendor name.