Pmwiki is a lightweight, self-hosted wiki engine whose vulnerability profile centers on its web-facing application layer, where recurring weakness classes involve improper input neutralization leading to cross-site scripting and code-injection conditions. The vendor's disclosures frequently acquire public exploit code, reflecting the accessibility of wiki instances to both researchers and adversaries seeking to demonstrate template and markup handling flaws. Live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pmwiki over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4453HIGH The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitrary code via PHP sequences in a crafted order parameter in a | Dec 22, 2011 | 7.5 | 71 | NO | YES |
CVE-2006-0479MEDIUM pmwiki.php in PmWiki 2.1 beta 20, with register_globals enabled, allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GPC vari | Jan 31, 2006 | 4.3 | 22 | NO | YES |
CVE-2010-4662MEDIUM PmWiki before 2.2.21 has XSS. | Feb 5, 2020 | 6.1 | 21 | NO | NO |
CVE-2005-3849MEDIUM Cross-site scripting (XSS) vulnerability in the Search module in PmWiki up to 2.0.12 allows remote attackers to inject arbitrary web script or HTML via the q parameter. | Nov 27, 2005 | 4.3 | 21 | NO | YES |
CVE-2006-2840MEDIUM Cross-site scripting (XSS) vulnerability in (1) uploads.php and (2) "url links" in PmWiki 2.1.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspe | Jun 6, 2006 | 6.8 | 18 | NO | NO |
CVE-2010-4748MEDIUM Cross-site scripting (XSS) vulnerability in pmwiki.php in PmWiki 2.2.20 allows remote attackers to inject arbitrary web script or HTML via the from parameter to Main/WikiSandbox. | Mar 1, 2011 | 4.3 | 16 | NO | NO |
Cross-site scripting (XSS) vulnerability in the table feature in PmWiki 2.2.15 allows remote authenticated users to inject arbitrary web script or HTML via the width attribute. | May 12, 2010 | 3.5 | 16 | NO | NO |
CVE-2006-4453MEDIUM Cross-site scripting (XSS) vulnerability in PmWiki before 2.1.18 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving "table markups". | Aug 30, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pmwiki.
Media articles that mention a CVE ID that affects a product developed by Pmwiki — matched by CVE ID, not by vendor name.