Pukiwiki is a lightweight wiki engine deployed in niche and specialized contexts, with its recorded exposure centered on its core product and variants such as Pukiwiki Plus. The durable signal reflects application-layer weaknesses common to wiki markup processors: cross-site scripting flaws in web-page generation and path-traversal issues in file handling, both characteristic of the parsing and directory-access patterns inherent to wiki platforms.
The number and severity of CVEs published that impact products developed by Pukiwiki over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27637MEDIUM Reflected cross-site scripting vulnerability in PukiWiki versions 1.5.1 to 1.5.3 allows a remote attacker to inject an arbitrary script via unspecified vectors. | Aug 23, 2022 | 6.1 | 21 | NO | NO |
CVE-2022-36350MEDIUM Stored cross-site scripting vulnerability in PukiWiki versions 1.3.1 to 1.5.3 allows a remote attacker to inject an arbitrary script via unspecified vectors. | Aug 23, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-34486HIGH Path traversal vulnerability in PukiWiki versions 1.4.5 to 1.5.3 allows a remote authenticated attacker with an administrative privilege to execute a malicious script via unspecifi | Aug 23, 2022 | 7.2 | 19 | NO | NO |
CVE-2011-3990MEDIUM Cross-site scripting (XSS) vulnerability in plugin/comment.inc.php in PukiWiki Plus! 1.4.7plus-u2-i18n and earlier allows remote attackers to inject arbitrary web script or HTML vi | Dec 22, 2011 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pukiwiki.
Media articles that mention a CVE ID that affects a product developed by Pukiwiki — matched by CVE ID, not by vendor name.