PT-2025-30189 · Unknown · Zavy86 Wikidocs

Matans

·

Published

2025-07-20

·

Updated

2025-07-21

·

CVE-2025-7887

CVSS v2.0
5.0
VectorAV:N/AC:L/Au:N/C:N/I:P/A:N

Name of the Vulnerable Software and Affected Versions:

Zavy86 WikiDocs versions through 1.0.78

Description:

A vulnerability exists in Zavy86 WikiDocs, potentially allowing for cross site scripting. The issue is located in the file `template.inc.php` and involves manipulation of the `path` argument. The attack can be initiated remotely. The exploit has been publicly disclosed.

Recommendations:

Versions prior to 1.0.78 should be updated.

Exploit

Fix

Code Injection

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-7887

Affected Products

Zavy86 Wikidocs