CVE Tools

Dokuwiki

18 CVEs tracked since 2009. Since Jun 2009, none of them reached CISA KEV.

Dokuwiki CVEs per month

Jun 2009 to Aug 2017. Point at a month, or focus the strip and use the arrow keys.
Dokuwiki CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2009-0610
2009-07null or fewer
2009-08null or fewer
2009-09null or fewer
2009-10null or fewer
2009-11null or fewer
2009-12null or fewer
2010-01null or fewer
2010-0230
2010-03null or fewer
2010-04null or fewer
2010-05null or fewer
2010-06null or fewer
2010-07null or fewer
2010-08null or fewer
2010-09null or fewer
2010-10null or fewer
2010-11null or fewer
2010-12null or fewer
2011-01null or fewer
2011-02null or fewer
2011-03null or fewer
2011-04null or fewer
2011-05null or fewer
2011-06null or fewer
2011-0710
2011-08null or fewer
2011-0910
2011-10null or fewer
2011-11null or fewer
2011-12null or fewer
2012-01null or fewer
2012-02null or fewer
2012-03null or fewer
2012-04null or fewer
2012-05null or fewer
2012-06null or fewer
2012-07null or fewer
2012-08null or fewer
2012-09null or fewer
2012-10null or fewer
2012-1110
2012-12null or fewer
2013-01null or fewer
2013-02null or fewer
2013-03null or fewer
2013-04null or fewer
2013-05null or fewer
2013-06null or fewer
2013-07null or fewer
2013-08null or fewer
2013-09null or fewer
2013-10null or fewer
2013-11null or fewer
2013-12null or fewer
2014-01null or fewer
2014-02null or fewer
2014-03null or fewer
2014-04null or fewer
2014-05null or fewer
2014-06null or fewer
2014-07null or fewer
2014-08null or fewer
2014-09null or fewer
2014-1040
2014-11null or fewer
2014-1210
2015-01null or fewer
2015-02null or fewer
2015-0310
2015-04null or fewer
2015-05null or fewer
2015-06null or fewer
2015-07null or fewer
2015-08null or fewer
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-12null or fewer
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-04null or fewer
2016-05null or fewer
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-1020
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-0830

Products

The products that kept showing up in Dokuwiki's monthly top three, with their CVEs summed over those months.

  1. Dokuwiki1810 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Dokuwiki.

  1. CVE-2026-26477An issue in Dokuwiki v.2025-05-14b "Librarian" [56.2] allows a remote attacker to cause a denial of service via the media_upload_xhr() function in the media.php file4.3
  2. CVE-2019-25338Dokuwiki 2018-04-22b - Username Enumeration5.3
  3. CVE-2023-34408DokuWiki before 2023-04-04a allows XSS via RSS titles.5.4
  4. CVE-2022-3123Cross-site Scripting (XSS) - Reflected in splitbrain/dokuwiki6.1
  5. CVE-2022-28919HTMLCreator release_stable_2020-07-29 was discovered to contain a cross-site scripting (XSS) vulnerability via the function _generateFilename.6.1
  6. CVE-2018-15474CSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier allows remote attackers to exfiltrate sensitive data and to ...9.6
  7. CVE-2017-18123The call parameter of /lib/exe/ajax.php in DokuWiki through 2017-02-19e does not properly encode user input, which leads to a reflected file download vulnerability, and allows remote attackers to r...8.6
  8. CVE-2017-12980DokuWiki through 2017-02-19c has stored XSS when rendering a malicious RSS or Atom feed, in /inc/parser/xhtml.php. An attacker can create or edit a wiki that uses RSS or Atom data from an attacker-...6.1
  9. CVE-2017-12979DokuWiki through 2017-02-19c has stored XSS when rendering a malicious language name in a code element, in /inc/parser/xhtml.php. An attacker can create or edit a wiki with this element to trigger ...6.1
  10. CVE-2017-12583DokuWiki through 2017-02-19b has XSS in the at parameter (aka the DATE_AT variable) to doku.php.6.1
  11. CVE-2016-7965DokuWiki 2016-06-26a and older uses $_SERVER[HTTP_HOST] instead of the baseurl setting as part of the password-reset URL. This can lead to phishing attacks. (A remote unauthenticated attacker can c...6.5
  12. CVE-2016-7964The sendRequest method in HTTPClient Class in file /inc/HTTPClient.php in DokuWiki 2016-06-26a and older, when media file fetching is enabled, has no way to restrict access to private networks. Thi...8.6
  13. CVE-2015-2172DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain privileges and add or delete ACL rules vi...6.5
  14. CVE-2014-9253The default file type whitelist configuration in conf/mime.conf in the Media Manager in DokuWiki before 2014-09-29b allows remote attackers to execute arbitrary web script or HTML by uploading an S...4.3
  15. CVE-2014-8761inc/template.php in DokuWiki before 2014-05-05a only checks for access to the root namespace, which allows remote attackers to access arbitrary images via a media file details ajax call.5.0

The record

Peak rank
#30 in Feb 2010
Busiest month shown
Oct 2014, 4 CVEs
Months with a KEV entry
0 since Jun 2009
Monthly snapshots
10 since 2009
Dokuwiki's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store