Twiki is a lightweight, self-hosted collaboration and knowledge-management platform with a modestly sized but prominent vulnerability footprint concentrated in its core product and community plugins such as ImageGalleryPlugin. The exposure recurs persistently through web-application vulnerability classes—principally cross-site scripting, cross-site request forgery, code injection, and input-handling flaws—that reflect the platform's role as a publicly accessible wiki and content-generation system. Vulnerabilities affecting Twiki tend to acquire public exploit code, consistent with the transparency and community scrutiny that open-source wiki platforms attract. Defenders should treat Twiki instances, particularly those exposed to untrusted networks or the internet, as requiring regular patching and should isolate administrative interfaces; current exploitation activity and severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Twiki over time
Signals from CVEs in this vendor scope (30 CVEs).
30 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1037HIGH The search function in TWiki 20030201 allows remote attackers to execute arbitrary commands via shell metacharacters in a search string. | Mar 1, 2005 | 10.0 | 76 | NO | YES |
CVE-2005-2877HIGH The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary code via shell metacharacters, as demonstrated via the rev par | Sep 16, 2005 | 7.5 | 75 | NO | YES |
CVE-2014-7236CRITICAL Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenableplugins parameter to do/view/Ma | Feb 17, 2020 | 9.1 | 71 | NO | YES |
CVE-2012-6330MEDIUM The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to cause a denial of service (memory consump | Jan 4, 2013 | 5.0 | 47 | NO | YES |
CVE-2008-5305HIGH Eval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable. | Dec 10, 2008 | 10.0 | 41 | NO | YES |
CVE-2008-3195MEDIUM Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows remote attackers to read arbitrary files | Sep 18, 2008 | 6.8 | 33 | NO | YES |
CVE-2005-3056CRITICAL TWiki allows arbitrary shell command execution via the Include function | Nov 1, 2019 | 9.8 | 32 | NO | NO |
CVE-2013-1751CRITICAL TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containing Perl backtick characters. | Nov 7, 2019 | 9.8 | 31 | NO | NO |
CVE-2006-3819HIGH Eval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arbitrary Perl code via an HTTP POST request containing a param | Jul 27, 2006 | 7.5 | 29 | NO | YES |
CVE-2011-3010MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the newtopic parameter in a WebCreat | Sep 30, 2011 | 4.3 | 28 | NO | YES |
Signals from CVEs in this vendor scope (30 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Twiki.
Media articles that mention a CVE ID that affects a product developed by Twiki — matched by CVE ID, not by vendor name.