← Vulnerability feed

Vulnerability record · CVE-2011-3010 · published 30 September 2011

CVE-2011-3010: Twiki cross-site scripting vulnerability

Twiki · Twiki

Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the newtopic parameter in a WebCreateNewTopic action, related to the TWiki.WebCreateNewTopicTemplate topic; or (2) the query string to SlideShow.pm in the SlideShowPlugin.

4.3 CVSS 2.0 Medium EPSS 5.5% · top 7.5% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
5.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Multiple cross-site scripting (XSS) vulnerabilities in TWiki before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the newtopic parameter in a WebCreateNewTopic action, related to the TWiki.WebCreateNewTopicTemplate topic; or (2) the query string to SlideShow.pm in the SlideShowPlugin.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-3010 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-5305Twiki code injection vulnerabilityEval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable.EPSS 4.6%10.0CVE-2004-1037TWiki search function allows remote command executionThe search function in TWiki 20030201 passes user-supplied search strings to a shell without sanitizing shell metacharacters, allowing command inject…EPSS 62%analysed9.8CVE-2013-1751Twiki improper input validation vulnerabilityTWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containing Perl ba…EPSS 4.9%9.8CVE-2005-3056Twiki injection vulnerabilityTWiki allows arbitrary shell command execution via the Include functionEPSS 3.5%9.1CVE-2014-7236TWiki Plugins.pm eval injection allows remote Perl code executionTWiki before 6.0.1 contains an eval injection flaw in lib/TWiki/Plugins.pm. The debugenableplugins parameter passed to do/view/Main/WebHome is evalua…EPSS 56%analysed9.0CVE-2006-6071Twiki vulnerabilityTWiki 4.0.5 and earlier, when running under Apache 1.3 using ApacheLogin with sessions and "ErrorDocument 401" redirects to a valid wiki topic, does …EPSS 2.2%7.5CVE-2006-3819Twiki vulnerabilityEval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arbitrary Perl code via an HTTP …EPSS 4.1%7.5CVE-2006-1386Twiki vulnerabilityThe (1) rdiff and (2) preview scripts in TWiki 4.0 and 4.0.1 ignore access control settings, which allows remote attackers to read restricted areas a…EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2011-3010), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.