Where
-Infinity
0

Vendor Risk Score

See how moinmo compares to other vendors in security performance

View Risk Score →

debian/moinmalicious SVG attachment causing stored XSS vulnerability in MoinMoin

Risk 64
Severity
8.7
First published (updated )

Debian Debian LinuxPath Traversal

Risk 89
Severity
9.8
First published (updated )

Canonical Ubuntu LinuxXSS

Risk 39
Severity
6.1
First published (updated )

Canonical Ubuntu LinuxXSS

Risk 39
Severity
6.1
First published (updated )

pip/moinXSS

Risk 39
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/moinXSS

Risk 39
Severity
6.1
First published (updated )

pip/moinXSS

Risk 39
Severity
6.1
First published (updated )

MoinMoinPath Traversal

Risk 43
Severity
6
First published (updated )

MoinMoinPath Traversal

Risk 41
Severity
6.4
First published (updated )

MoinMoinMalicious File Upload

Risk 47
Severity
6.2
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MoinMoinsecurity/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain…

Risk 43
Severity
6
First published (updated )

MoinMoinXSS

Risk 39
Severity
6.1
First published (updated )

MoinMoinXSS

Risk 39
Severity
6.1
First published (updated )

MoinMoinXSS

Risk 39
Severity
6.1
First published (updated )

MoinMoinXSS

Risk 39
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MoinMoinMoinMoin 1.7.1 allows remote attackers to bypass the textcha protection mechanism by modifying the t…

Risk 26
Severity
5
First published (updated )

pip/moinXSS

Risk 36
Severity
5.4
First published (updated )

MoinMoinMoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circu…

Risk 45
Severity
7.5
First published (updated )

MoinMoinThe default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does not pre…

Risk 54
Severity
7.5
First published (updated )

pip/moinInfoleak

Risk 45
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

MoinMoinMoinMoin before 1.8.7 and 1.9.x before 1.9.2 does not properly sanitize user profiles, which has uns…

Risk 55
Severity
7.5
First published (updated )

MoinMoinUnspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.…

Risk 49
Severity
6.8
First published (updated )

MoinMoin MoinMoinXSS

Risk 39
Severity
6.1
First published (updated )

pip/moinMoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, whic…

Risk 45
Severity
7.5
First published (updated )

pip/moinThe rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, wh…

Risk 28
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/moinThe password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and pytho…

Risk 45
Severity
7.5
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203