Nancy Wichmann maintains a narrow set of web-based documentation and reference products, including realname, announcements, glossary, and taxonomy materials, where vulnerabilities cluster around application-layer input-handling and information-disclosure issues characteristic of web content management. The recurring weakness classes—cross-site scripting and sensitive-information exposure—reflect the challenges of sanitizing user-supplied content and managing access to documentation in web environments. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nancy Wichmann over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-2302MEDIUM Site Documentation (Sitedoc) module for Drupal 6.x-1.x before 6.x-1.4 does not properly check the save location when archiving, which allows remote attackers to obtain sensitive in | Jul 25, 2012 | 5.0 | 17 | NO | NO |
CVE-2012-2298MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the RealName module 6.x-1.x before 6.x-1.5 for Drupal allow remote attackers to inject arbitrary web script or HTML via vecto | Aug 14, 2012 | 4.3 | 16 | NO | NO |
CVE-2012-2339MEDIUM Cross-site scripting (XSS) vulnerability in the Glossary module 6.x-1.x before 6.x-1.8 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vec | May 21, 2012 | 4.3 | 16 | NO | NO |
The Announcements module 6.x-1.x before 6.x-1.5 for Drupal allows remote authenticated users with the "access announcements" permission to bypass node access restrictions and possi | Oct 31, 2012 | 3.5 | 15 | NO | NO |
CVE-2009-4524MEDIUM Cross-site scripting (XSS) vulnerability in the RealName module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via a realname (aka | Dec 31, 2009 | 4.3 | 14 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in the Taxonomy List module 6.x-1.x before 6.x-1.4 for Drupal allow remote authenticated users with create or edit taxonomy term | Jun 27, 2012 | 2.1 | 13 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nancy Wichmann.
Media articles that mention a CVE ID that affects a product developed by Nancy Wichmann — matched by CVE ID, not by vendor name.