Information on source package dokuwiki

Available versions

ReleaseVersion
jessie0.0.20140505.a+dfsg-4+deb8u1
buster0.0.20180422.a-2
bullseye0.0.20180422.a-2.1
bookworm0.0.20220731.a-2
trixie0.0.20220731.a-3
sid0.0.20220731.a-3

Open issues

BugjessiebusterbullseyebookwormtrixiesidDescription
TEMP-0780817-7C5137vulnerable (no DSA)fixedfixedfixedfixedfixedInsufficient escaping in user manager allows XSS attack
CVE-2023-34408vulnerablevulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedDokuWiki before 2023-04-04a allows XSS via RSS titles.
CVE-2022-28919vulnerablevulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedHTMLCreator release_stable_2020-07-29 was discovered to contain a cros ...
CVE-2017-12980vulnerable (no DSA)fixedfixedfixedfixedfixedDokuWiki through 2017-02-19c has stored XSS when rendering a malicious ...
CVE-2017-12979vulnerable (no DSA)fixedfixedfixedfixedfixedDokuWiki through 2017-02-19c has stored XSS when rendering a malicious ...
CVE-2014-9253vulnerable (no DSA)fixedfixedfixedfixedfixedThe default file type whitelist configuration in conf/mime.conf in the ...

Open unimportant issues

BugjessiebusterbullseyebookwormtrixiesidDescription
CVE-2024-33103vulnerablevulnerablevulnerablevulnerablevulnerablevulnerableAn arbitrary file upload vulnerability in the Media Manager component ...
CVE-2016-7965vulnerablevulnerablevulnerablevulnerablevulnerablevulnerableDokuWiki 2016-06-26a and older uses $_SERVER[HTTP_HOST] instead of the ...

Resolved issues

BugDescription
TEMP-0434134-B27890dokuwiki XSS in spellchecker
TEMP-0410557-009D67dokuwiki conf directory accessible by web users
TEMP-0000000-52FF39dokuwiki ACL bypass
CVE-2022-3123Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain ...
CVE-2017-18123The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19 ...
CVE-2017-12583DokuWiki through 2017-02-19b has XSS in the at parameter (aka the DATE ...
CVE-2015-2172DokuWiki before 2014-05-05d and before 2014-09-29c does not properly c ...
CVE-2014-8764DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP ...
CVE-2014-8763DokuWiki before 2014-05-05b, when using Active Directory for LDAP auth ...
CVE-2014-8762The ajax_mediadiff function in DokuWiki before 2014-05-05a allows remo ...
CVE-2014-8761inc/template.php in DokuWiki before 2014-05-05a only checks for access ...
CVE-2012-3354doku.php in DokuWiki, as used in Fedora 16, 17, and 18, when certain P ...
CVE-2012-2129Cross-site scripting (XSS) vulnerability in doku.php in DokuWiki 2012- ...
CVE-2012-2128Cross-site request forgery (CSRF) vulnerability in doku.php in DokuWik ...
CVE-2012-0283Cross-site scripting (XSS) vulnerability in the tpl_mediaFileList func ...
CVE-2011-2510Cross-site scripting (XSS) vulnerability in the RSS embedding feature ...
CVE-2010-0289Multiple cross-site request forgery (CSRF) vulnerabilities in the ACL ...
CVE-2010-0288A typo in the administrator permission check in the ACL Manager plugin ...
CVE-2010-0287Directory traversal vulnerability in the ACL Manager plugin (plugins/a ...
CVE-2009-1960inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, w ...
CVE-2008-5186The set_language_path function in geshi.php in Generic Syntax Highligh ...
CVE-2006-6965CRLF injection vulnerability in lib/exe/fetch.php in DokuWiki 2006-03- ...
CVE-2006-5099lib/exec/fetch.php in DokuWiki before 2006-03-09e, when conf[imconvert ...
CVE-2006-5098lib/exec/fetch.php in DokuWiki before 2006-03-09e allows remote attack ...
CVE-2006-4679DokuWiki before 2006-03-09c enables the debug feature by default, whic ...
CVE-2006-4675Unrestricted file upload vulnerability in lib/exe/media.php in DokuWik ...
CVE-2006-4674Direct static code injection vulnerability in doku.php in DokuWiki bef ...
CVE-2006-2945Unspecified vulnerability in the user profile change functionality in ...
CVE-2006-2878The spellchecker (spellcheck.php) in DokuWiki 2006/06/04 and earlier a ...
CVE-2006-1165Cross-site scripting (XSS) vulnerability in the mediamanager module in ...
CVE-2004-2560DokuWiki before 2004-10-19, when used on a web server that permits exe ...
CVE-2004-2559DokuWiki before 2004-10-19 allows remote attackers to access administr ...

Security announcements

DSA / DLADescription
DLA-1413-1dokuwiki - security update
DLA-1269-1dokuwiki - security update
DSA-3059-1dokuwiki - security update
DLA-79-1dokuwiki - security update
DSA-1976-1dokuwiki - several vulnerabilities

Search for package or bug name: Reporting problems