CVE-2014-7236: Twiki

Critical severity, CVSS 9.1. EPSS: 55.6% chance of exploitation in the next 30 days.

Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenableplugins parameter to do/view/Main/WebHome.

Affected products

  • Twiki Twiki: from 4.0, up to and including 4.0.5; from 4.1, up to and including 4.1.2; from 4.2, up to and including 4.2.4; from 4.3, up to and including 4.3.2; from 5.0, up to and including 5.0.2; from 5.1.0, up to and including 5.1.4; …

Published 2020-02-17. Last modified 2026-06-17.