Vulnerabilities (CVE)

Filtered by vendor Twiki Subscribe
Filtered by product Twiki
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-7236 1 Twiki 1 Twiki 2020-02-20 6.4 MEDIUM 9.1 CRITICAL
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenableplugins parameter to do/view/Main/WebHome.
CVE-2013-1751 1 Twiki 1 Twiki 2019-11-08 10.0 HIGH 9.8 CRITICAL
TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containing Perl backtick characters.
CVE-2005-3056 1 Twiki 1 Twiki 2019-11-05 7.5 HIGH 9.8 CRITICAL
TWiki allows arbitrary shell command execution via the Include function