moin
PyPI41 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting moinpage 1 of 1
- CVE-2004-0708NONECVSS 0.0✓ Fixed in 1.2.22004-07-27
MoinMoin 1.2.1 and earlier allows remote attackers to gain privileges by creating a user with the same name as an existing group that has higher privileges.
- CVE-2004-1462NONECVSS 0.0✓ Fixed in 1.2.32004-12-31
Unknown vulnerability in MoinMoin 1.2.2 and earlier allows remote attackers to gain unauthorized access to administrator functions such as (1) revert and (2) delete.
- CVE-2004-1463NONECVSS 0.0✓ Fixed in 1.2.32004-12-31
Unknown vulnerability in the PageEditor in MoinMoin 1.2.2 and earlier, related to Access Control Lists (ACL), has unknown impact.
- CVE-2007-0857NONECVSS 0.0✓ Fixed in 1.5.72007-02-08
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin before 1.5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the page info, or the page name in a (2) AttachFile, (3) RenamePage, or (4) LocalSiteMap act…
- CVE-2007-0901NONECVSS 0.0✓ Fixed in 1.5.82007-02-13
Multiple cross-site scripting (XSS) vulnerabilities in Info pages in MoinMoin 1.5.7 allow remote attackers to inject arbitrary web script or HTML via the (1) hitcounts and (2) general parameters, different vectors than CVE-2007-0857. NOTE…
- CVE-2007-0902NONECVSS 0.0✓ Fixed in 1.5.82007-02-13
vulnerable: 1.5.7
Unspecified vulnerability in the "Show debugging information" feature in MoinMoin 1.5.7 allows remote attackers to obtain sensitive information. NOTE: the provenance of this information is unknown; the details are obtained solely from thi…
- CVE-2007-2637NONECVSS 0.0✓ Fixed in 1.5.82007-05-13
MoinMoin before 20070507 does not properly enforce ACLs for calendars and includes, which allows remote attackers to read certain pages via unspecified vectors.
- CVE-2008-0780NONECVSS 0.0✓ Fixed in 1.6.12008-02-14
Cross-site scripting (XSS) vulnerability in MoinMoin 1.5.x through 1.5.8 and 1.6.x before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the login action.
- CVE-2008-0781NONECVSS 0.02008-02-14
Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.5.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) message, (2) pagename, and (3) target filenames.
- CVE-2008-0782NONECVSS 0.02008-02-14
Directory traversal vulnerability in MoinMoin 1.5.8 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the MOIN_ID user ID in a cookie for a userform action. NOTE: this issue can be leveraged for PHP co…
- CVE-2008-1098NONECVSS 0.02008-03-05
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.5.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) certain input processed by formatter/text_gedit.py (aka the gui editor formatter); (2) …
- CVE-2008-1099NONECVSS 0.02008-03-05
_macro_Getval in wikimacro.py in MoinMoin 1.5.8 and earlier does not properly enforce ACLs, which allows remote attackers to read protected pages.
- CVE-2008-1937NONECVSS 0.0✓ Fixed in 1.7.12008-04-25
vulnerable: 1.7
The user form processing (userform.py) in MoinMoin before 1.6.3, when using ACLs or a non-empty superusers list, does not properly manage users, which allows remote attackers to gain privileges.
- CVE-2008-3381NONECVSS 0.0✓ Fixed in 1.7.12008-07-30
vulnerable: 1.7.0
Multiple cross-site scripting (XSS) vulnerabilities in macro/AdvancedSearch.py in moin (and MoinMoin) 1.6.3 and 1.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVE-2008-6548NONECVSS 0.02009-03-30
vulnerable: 1.8.4 ... 2.0.0b3 (20 versions)
The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via unknown vectors.
- CVE-2008-6549NONECVSS 0.0✓ Fixed in 1.6.12009-03-30
The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are not thread-safe, which allows remote attackers to cause a denial of service (segmentation fault and c…
- CVE-2008-6603NONECVSS 0.0✓ Fixed in 1.7.12009-04-03
vulnerable: 1.7
MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote attackers to bypass intended access restrictions, a different vulnerability than CVE-2008-1937.
- CVE-2009-0260NONECVSS 0.0✓ Fixed in 1.8.12009-01-23
Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin before 1.8.1 allow remote attackers to inject arbitrary web script or HTML via an AttachFile action to the WikiSandBox component with (1) the rename pa…
- CVE-2009-0312NONECVSS 0.0✓ Fixed in 1.8.22009-01-28
Cross-site scripting (XSS) vulnerability in the antispam feature (security/antispam.py) in MoinMoin 1.7 and 1.8.1 allows remote attackers to inject arbitrary web script or HTML via crafted, disallowed content.
- CVE-2009-1482NONECVSS 0.0✓ Fixed in 1.8.32009-04-29
Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) an AttachFile sub-action in the error_msg function or (2) multi…
- CVE-2009-4762NONECVSS 0.0✓ Fixed in 1.8.32010-03-29
MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchical ACLs, which allows remote attackers to bypass intended access restrictions by requesting an item…
- CVE-2010-0667NONECVSS 0.0✓ Fixed in 1.9.12010-02-26
vulnerable: 1.9.0
MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vec…
- CVE-2010-0668NONECVSS 0.0✓ Fixed in 1.9.22010-02-26
vulnerable: 1.8.4, 1.8.5, 1.8.6, 1.9.0, 1.9.1
Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors, related to configurations that have a non-empty superuser list, the xmlrpc action enabled, the Syn…
- CVE-2010-0669NONECVSS 0.0✓ Fixed in 1.9.22010-02-26
vulnerable: 1.8.4, 1.8.5, 1.8.6, 1.9.0, 1.9.1
MoinMoin before 1.8.7 and 1.9.x before 1.9.2 does not properly sanitize user profiles, which has unspecified impact and attack vectors.
- CVE-2010-0717NONECVSS 0.0✓ Fixed in 1.8.72010-02-26
vulnerable: 1.8.4, 1.8.5, 1.8.6
The default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does not prevent unsafe package actions, which has unspecified impact and attack vectors.
- CVE-2010-0828NONECVSS 0.0✓ Fixed in 1.9.32010-04-05
vulnerable: 1.8.4 ... 1.9.2 (7 versions)
Cross-site scripting (XSS) vulnerability in action/Despam.py in the Despam action module in MoinMoin 1.8.7 and 1.9.2 allows remote authenticated users to inject arbitrary web script or HTML by creating a page with a crafted URI.
- CVE-2010-2487NONECVSS 0.0✓ Fixed in 1.9.32010-08-05
vulnerable: 1.8.4 ... 1.9.2 (7 versions)
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, 1.8.x before 1.8.8, and 1.9.x before 1.9.3 allow remote attackers to inject arbitrary web script or HTML via crafted content, related to (1) Page.py, (2) Pa…
- CVE-2010-2969NONECVSS 0.0✓ Fixed in 1.9.32010-08-05
vulnerable: 1.9.0, 1.9.1, 1.9.2
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, and 1.9.x before 1.9.3, allow remote attackers to inject arbitrary web script or HTML via crafted content, related to (1) action/LikePages.py, (2) action/ch…
- CVE-2010-2970NONECVSS 0.0✓ Fixed in 1.9.32010-08-05
vulnerable: 1.9.0, 1.9.1, 1.9.2
Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.9.x before 1.9.3 allow remote attackers to inject arbitrary web script or HTML via crafted content, related to (1) action/SlideShow.py, (2) action/anywikidraw.py, and (3) ac…
- CVE-2011-1058NONECVSS 0.0✓ Fixed in 1.9.32011-02-22
vulnerable: 1.8.4 ... 1.9.2 (7 versions)
Cross-site scripting (XSS) vulnerability in the reStructuredText (rst) parser in parser/text_rst.py in MoinMoin before 1.9.3, when docutils is installed or when "format rst" is set, allows remote attackers to inject arbitrary web script or…
- CVE-2012-4404NONECVSS 0.0✓ Fixed in 1.9.52012-09-10
vulnerable: 1.9.0, 1.9.1, 1.9.2, 1.9.3, 1.9.4
security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be trea…
- CVE-2012-6080NONECVSS 0.0✓ Fixed in 1.9.62013-01-03
vulnerable: 1.9.3, 1.9.4, 1.9.5
Directory traversal vulnerability in the _do_attachment_move function in the AttachFile action (action/AttachFile.py) in MoinMoin 1.9.3 through 1.9.5 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a file name.
- CVE-2012-6081NONECVSS 0.0✓ Fixed in 1.9.62013-01-03
vulnerable: 1.8.4 ... 1.9.5 (10 versions)
Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to execute ar…
- CVE-2012-6082NONECVSS 0.0✓ Fixed in 1.9.62013-01-03
vulnerable: 1.8.4 ... 1.9.5 (10 versions)
Cross-site scripting (XSS) vulnerability in the rsslink function in theme/__init__.py in MoinMoin 1.9.5 allows remote attackers to inject arbitrary web script or HTML via the page name in a rss link.
- CVE-2012-6495NONECVSS 0.0✓ Fixed in 1.9.62013-01-03
vulnerable: 1.8.4 ... 1.9.5 (10 versions)
Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anywikidraw.py) actions in MoinMoin before 1.9.6 allow remote authenticated users with write permissions to overwrite arbit…
- CVE-2016-7146MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.9.92016-11-10
vulnerable: 1.8.4 ... 1.9.8 (13 versions)
MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation or crafted URL" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=fckdialog&dialog=attachment (via pa…
- CVE-2016-7148MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.9.92016-11-10
vulnerable: 1.8.4 ... 1.9.8 (13 versions)
MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=AttachFile (via page name) component.
- CVE-2016-9119MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.9.82017-01-30
vulnerable: 1.8.4 ... 1.9.7 (12 versions)
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVE-2017-5934MEDIUMCVSS 6.1✓ Fixed in 1.9.102018-10-15
vulnerable: 1.8.4 ... 1.9.9 (14 versions)
Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVE-2020-15275HIGHCVSS 8.7EG 8.7✓ Fixed in 1.9.112020-11-11
vulnerable: 1.8.4 ... 1.9.9 (15 versions)
MoinMoin is a wiki engine. In MoinMoin before version 1.9.11, an attacker with write permissions can upload an SVG file that contains malicious javascript. This javascript will be executed in a user's browser when the user is viewing that …
- CVE-2020-25074CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.9.112020-11-10
vulnerable: 1.8.4 ... 1.9.10 (15 versions)
The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload attachments to the wiki can use this to achieve remote code execution.
Check whether moin is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for moin CVEs against the assets you own.
Start Free Scan →