foswiki CVE Vulnerabilities & Metrics

Focus on foswiki vulnerabilities and metrics.

Last updated: 08 Mar 2026, 23:25 UTC

About foswiki Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with foswiki. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total foswiki CVEs: 4
Earliest CVE date: 30 Apr 2009, 20:30 UTC
Latest CVE date: 21 Feb 2026, 06:17 UTC

Latest CVE reference: CVE-2026-2861

Rolling Stats

30-day Count (Rolling): 1
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical foswiki CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.03

Max CVSS: 6.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 3
4.0-6.9 5
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS foswiki CVEs

These are the five CVEs with the highest CVSS scores for foswiki, sorted by severity first and recency.

All CVEs for foswiki

CVE-2026-2861 foswiki vulnerability CVSS: 5.0 21 Feb 2026, 06:17 UTC

A vulnerability was detected in Foswiki up to 2.1.10. The affected element is an unknown function of the component Changes/Viewfile/Oops. The manipulation results in information disclosure. It is possible to launch the attack remotely. The exploit is now public and may be used. Upgrading to version 2.1.11 is sufficient to fix this issue. The patch is identified as 31aeecb58b64/d8ed86b10e46. Upgrading the affected component is recommended.

CVE-2023-33756 foswiki vulnerability CVSS: 0 08 Aug 2023, 15:15 UTC

An issue in the SpreadSheetPlugin component of Foswiki v2.1.7 and below allows attackers to execute a directory traversal.

CVE-2023-24698 foswiki vulnerability CVSS: 0 08 Aug 2023, 15:15 UTC

Insufficient parameter validation in the Foswiki::Sandbox component of Foswiki v2.1.7 and below allows attackers to perform a directory traversal via supplying a crafted web request.

CVE-2013-1666 foswiki vulnerability CVSS: 6.8 01 Nov 2019, 17:15 UTC

Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro.

CVE-2012-6330 foswiki vulnerability CVSS: 5.0 04 Jan 2013, 21:55 UTC

The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows remote attackers to cause a denial of service (memory consumption) via a large integer in a %MAKETEXT% macro.

CVE-2012-1004 foswiki vulnerability CVSS: 2.1 08 Feb 2012, 04:11 UTC

Multiple cross-site scripting (XSS) vulnerabilities in UI/Register.pm in Foswiki before 1.1.5 allow remote authenticated users with CHANGE privileges to inject arbitrary web script or HTML via the (1) text, (2) FirstName, (3) LastName, (4) OrganisationName, (5) OrganisationUrl, (6) Profession, (7) Country, (8) State, (9) Address, (10) Location, (11) Telephone, (12) VoIP, (13) InstantMessagingIM, (14) Email, (15) HomePage, or (16) Comment parameter. NOTE: some of these details are obtained from third party information.

CVE-2010-4215 foswiki vulnerability CVSS: 6.5 17 Nov 2010, 01:00 UTC

UI/Manage.pm in Foswiki 1.1.0 and 1.1.1 allows remote authenticated users to gain privileges by modifying the GROUP and ALLOWTOPICCHANGE preferences in the topic preferences for Main.AdminGroup.

CVE-2009-1434 foswiki vulnerability CVSS: 6.8 30 Apr 2009, 20:30 UTC

Cross-site request forgery (CSRF) vulnerability in Foswiki before 1.0.5 allows remote attackers to hijack the authentication of arbitrary users for requests that modify pages, change permissions, or change group memberships, as demonstrated by a URL for a (1) save or (2) view script in the SRC attribute of an IMG element, a related issue to CVE-2009-1339.