Wikidsystems operates a narrowly focused two-factor authentication platform serving enterprise deployments, where vulnerabilities cluster in web-application and authentication-handling components. The durable signal centers on recurrent input-validation and session-management weaknesses—cross-site scripting, SQL injection, and cross-site request forgery—that reflect the web-facing nature of authentication servers and portal interfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wikidsystems over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17120MEDIUM A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via | Oct 17, 2019 | 6.1 | 45 | NO | NO |
CVE-2019-17119HIGH Multiple SQL injection vulnerabilities in Logs.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allow authenticated users to execute arbitrary SQL commands via the source or | Oct 17, 2019 | 8.8 | 28 | NO | NO |
CVE-2019-17117HIGH A SQL injection vulnerability in processPref.jsp in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows an authenticated user to execute arbitrary SQL commands via the processPr | Oct 17, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-16917HIGH WiKID Enterprise 2FA (two factor authentication) Enterprise Server through 4.2.0-b2047 is vulnerable to SQL injection through the searchDevices.jsp endpoint. The uid and domain par | Oct 17, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-17118HIGH A CSRF issue in WiKID 2FA Enterprise Server through 4.2.0-b2053 allows a remote attacker to trick an authenticated user into performing unintended actions such as (1) create or del | Oct 17, 2019 | 8.8 | 25 | NO | NO |
CVE-2019-17115MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML that is trigger | Oct 17, 2019 | 6.1 | 21 | NO | NO |
CVE-2019-17116MEDIUM A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allow remote attackers to inject arbitrary web script or HTML via | Oct 17, 2019 | 6.1 | 20 | NO | NO |
CVE-2019-17114MEDIUM A stored and reflected cross-site scripting (XSS) vulnerability in WiKID 2FA Enterprise Server through 4.2.0-b2047 allows remote attackers to inject arbitrary web script or HTML vi | Oct 17, 2019 | 6.1 | 20 | NO | NO |
CVE-2008-4763MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in sample.php in WiKID wClient-PHP 3.0-2 and earlier allow remote attackers to inject arbitrary web script or HTML via the PHP_S | Oct 28, 2008 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wikidsystems.
Media articles that mention a CVE ID that affects a product developed by Wikidsystems — matched by CVE ID, not by vendor name.