Zavy86 WikiDocs Cross-Site Scripting Vulnerability in template.inc.php

Vulnerability

A reflected cross-site scripting vulnerability has been identified in Zavy86 WikiDocs versions through 1.0.78. The issue arises in the file template.inc.php, where the path argument is not properly sanitized before being outputted. This flaw allows remote attackers to inject malicious scripts that are executed in the context of the user's session.

Impact

Exploitation of this vulnerability allows for reflected cross-site scripting, where injected scripts are executed immediately in the context of the victim's browser session.

Reproduction

The vulnerability can be reproduced by sending a request to the WikiDocs home page with a crafted path argument that includes script tags. The application does not escape the HTML properly, allowing the injected script to run.

Added: Jul 20, 2025, 1:02 PM
Updated: Jul 20, 2025, 1:02 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.8
remediation
0.0
relevance
0.3
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.