Wikindx Project maintains a focused bibliography and reference-management application whose vulnerability footprint centers on input-handling weaknesses within web-facing components, primarily cross-site scripting flaws. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wikindx Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3277HIGH Unspecified vulnerability in the localization before 1.2 module for WIKINDX allows attackers to access certain administrative capabilities via unknown vectors. | Jun 19, 2007 | 10.0 | 25 | NO | NO |
CVE-2019-13588MEDIUM A cross-site scripting (XSS) vulnerability in getPagingStart() in core/lists/PAGING.php in WIKINDX before 5.8.2 allows remote attackers to inject arbitrary web script or HTML via t | Jul 26, 2019 | 6.1 | 21 | NO | NO |
CVE-2019-12930MEDIUM A cross-site scripting (XSS) vulnerability in noMenu() and noSubMenu() in core/navigation/MENU.php in WIKINDX prior to version 5.8.1 allows remote attackers to inject arbitrary web | Jul 8, 2019 | 6.1 | 21 | NO | NO |
CVE-2021-3340MEDIUM A cross-site scripting (XSS) vulnerability in many forms of Wikindx before 5.7.0 and 6.x through 6.4.0 allows remote attackers to inject arbitrary web script or HTML via the messag | Feb 1, 2021 | 6.1 | 19 | NO | NO |
CVE-2019-9961MEDIUM A cross-site scripting (XSS) vulnerability in ressource view in core/modules/resource/RESOURCEVIEW.php in Wikindx prior to version 5.7.0 allows remote attackers to inject arbitrary | Mar 26, 2019 | 6.1 | 17 | NO | NO |
CVE-2004-2506MEDIUM Unparsed web content delivery vulnerability in WIKINDX before 0.9.9g allows remote attackers to obtain sensitive information via a direct HTTP request to the config.inc file. | Dec 31, 2004 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wikindx Project.
Media articles that mention a CVE ID that affects a product developed by Wikindx Project — matched by CVE ID, not by vendor name.