Wikkawiki is a lightweight, open-source wiki engine with a modest but persistent vulnerability footprint concentrated in a single product line. Its disclosures recur around web-application weaknesses including cross-site request forgery, path traversal, and information exposure, reflecting the input-handling and access-control demands of collaborative wiki software. The vendor's vulnerabilities frequently acquire public exploit tooling, making timely patching important for installations exposed to untrusted networks; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wikkawiki over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4451MEDIUM libs/Wakka.class.php in WikkaWiki 1.3.1 and 1.3.2, when the spam_logging option is enabled, allows remote attackers to write arbitrary PHP code to the spamlog_path file via the Use | Sep 5, 2012 | 4.3 | 40 | NO | YES |
CVE-2011-4452MEDIUM Cross-site request forgery (CSRF) vulnerability in the AdminUsers component in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to hijack the authentication of administrators for | Sep 5, 2012 | 6.8 | 33 | NO | YES |
CVE-2011-4450MEDIUM Directory traversal vulnerability in handlers/files.xml/files.xml.php in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to read or delete arbitrary files via a non-initial .. (d | Sep 5, 2012 | 6.4 | 33 | NO | YES |
CVE-2011-4449MEDIUM actions/files/files.php in WikkaWiki 1.3.1 and 1.3.2, when INTRANET_MODE is enabled, supports file uploads for file extensions that are typically absent from an Apache HTTP Server | Sep 5, 2012 | 6.8 | 33 | NO | YES |
CVE-2011-4448HIGH SQL injection vulnerability in actions/usersettings/usersettings.php in WikkaWiki 1.3.1 and 1.3.2 allows remote attackers to execute arbitrary SQL commands via the default_comment_ | Sep 5, 2012 | 7.5 | 33 | NO | YES |
CVE-2007-2613HIGH WikkaWiki (Wikka Wiki) before 1.1.6.3 allows attackers in a shared virtual host server environment to upload and execute an arbitrary configuration file by modifying the WAKKA_CONF | May 11, 2007 | 8.3 | 22 | NO | NO |
CVE-2005-4255MEDIUM Cross-site scripting (XSS) vulnerability in TextSearch in WikkaWiki 1.1.6.0 allows remote attackers to inject arbitrary web script or HTML via a hex-encoded phrase parameter. | Dec 15, 2005 | 4.3 | 21 | NO | YES |
CVE-2007-2612HIGH SQL injection vulnerability in libs/Wakka.class.php in WikkaWiki (Wikka Wiki) before 1.1.6.3 allows remote attackers to execute arbitrary SQL commands via the limit parameter. NOT | May 11, 2007 | 7.5 | 19 | NO | NO |
CVE-2006-7049HIGH The Method method in WikkaWiki (Wikka Wiki) before 1.1.6.2 calls the strstr and strrpos functions with the wrong argument order, which allows remote attackers to bypass intended ac | Feb 24, 2007 | 7.5 | 19 | NO | NO |
CVE-2006-7050MEDIUM Cross-site scripting (XSS) vulnerability in WikkaWiki (Wikka Wiki) before 1.1.6.2 allows remote attackers to inject arbitrary javascript via (1) events in forced links (url paramet | Feb 24, 2007 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wikkawiki.
Media articles that mention a CVE ID that affects a product developed by Wikkawiki — matched by CVE ID, not by vendor name.