Releases90
Frequency1 week 5 days
Last Release
Stars499
๐Ÿ“— Just a databaseless markdown flat-file wiki engine

CVE History

CVEPublishedCVSS v3CVSS v2
4.3 MEDIUM5 MEDIUM

A vulnerability has been found in Zavy86 WikiDocs up to 1.0.78 and classified as problematic. This vulnerability affects unknown code of the file template.inc.php. The manipulation of the argument path leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

4.7 MEDIUM5.8 MEDIUM

A vulnerability has been found in Zavy86 WikiDocs up to 1.0.77 and classified as critical. Affected by this vulnerability is the function image_drop_upload_ajax/image_delete_ajax of the file submit.php. The manipulation leads to path traversal. The attack can be launched remotely. Upgrading to version 1.0.78 is able to address this issue. The identifier of the patch is 98ea9ee4a2052c4327f89d2f7688cc1b5749450d. It is recommended to upgrade the affected component.

5.4 MEDIUMโ€”

WikiDocs before 1.0.65 allows stored XSS by authenticated users via data that comes after $$\\, which is mishandled by a KaTeX parser.

6.1 MEDIUM4.3 MEDIUM

WikiDocs version 0.1.18 has multiple reflected XSS vulnerabilities on different pages.

8.8 HIGH6.5 MEDIUM

WikiDocs version 0.1.18 has an authenticated remote code execution vulnerability. An attacker can upload a malicious file using the image upload form through index.php.