Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Twiki

First CVE: Feb 23, 2005Active for: 21 yearsTotal CVEs: 30
44.9
VTI Score
High

Twiki is a lightweight, self-hosted collaboration and knowledge-management platform with a modestly sized but prominent vulnerability footprint concentrated in its core product and community plugins such as ImageGalleryPlugin. The exposure recurs persistently through web-application vulnerability classes—principally cross-site scripting, cross-site request forgery, code injection, and input-handling flaws—that reflect the platform's role as a publicly accessible wiki and content-generation system. Vulnerabilities affecting Twiki tend to acquire public exploit code, consistent with the transparency and community scrutiny that open-source wiki platforms attract. Defenders should treat Twiki instances, particularly those exposed to untrusted networks or the internet, as requiring regular patching and should isolate administrative interfaces; current exploitation activity and severity figures are shown alongside this summary.

FAUCET AI Generated
30
Total CVEs
More Total CVEs than 97% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Twiki over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 23, 2005
21 years ago
Most Recent CVE
Feb 17, 2020
2,349 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (30 CVEs).

30 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-1037HIGH
The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string.
Mar 1, 200510.076NOYES
CVE-2005-2877HIGH
The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metacharacters, as demonstrated via the rev par
Sep 16, 20057.575NOYES
CVE-2014-7236CRITICAL
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenableplugins parameter to do/view/Ma
Feb 17, 20209.171NOYES
CVE-2012-6330MEDIUM
The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to cause a denial of service (memory consump
Jan 4, 20135.047NOYES
CVE-2008-5305HIGH
Eval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable.
Dec 10, 200810.041NOYES
CVE-2008-3195MEDIUM
Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows remote attackers to read arbitrary files
Sep 18, 20086.833NOYES
CVE-2005-3056CRITICAL
TWiki allows arbitrary shell command execution via the Include function
Nov 1, 20199.832NONO
CVE-2013-1751CRITICAL
TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containing Perl backtick characters.
Nov 7, 20199.831NONO
CVE-2006-3819HIGH
Eval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arbitrary Perl code via an HTTP POST request containing a param
Jul 27, 20067.529NOYES
CVE-2011-3010MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the newtopic parameter in a WebCreat
Sep 30, 20114.328NOYES
View all 30 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products30 CVEs
67%
23%
10%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (13.3%)
Unknown26 (86.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (13.3%)
High0 (0.0%)
Unknown26 (86.7%)
User Interaction
None3 (10.0%)
Unknown26 (86.7%)
Required1 (3.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (13.3%)
Unknown26 (86.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (30 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
10.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
12 CVEs
40.0% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Twiki.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Twiki — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Twiki's Products

View all 2 CNAs →

Top CWEs