CVE-2026-26477

An issue in Dokuwiki v.2025-05-14b "Librarian" [56.2] allows a remote attacker to cause a denial of service via the media_upload_xhr() function in the media.php file
Configurations

Configuration 1 (hide)

cpe:2.3:a:dokuwiki:dokuwiki:2025-05-14b:*:*:*:*:*:*:*

History

09 Apr 2026, 00:16

Type Values Removed Values Added
References () https://github.com/Hebing123/cve/issues/94 - () https://github.com/Hebing123/cve/issues/94 - Exploit, Third Party Advisory
References () https://github.com/dokuwiki/dokuwiki/releases/tag/release-2025-05-14b - () https://github.com/dokuwiki/dokuwiki/releases/tag/release-2025-05-14b - Release Notes
CPE cpe:2.3:a:dokuwiki:dokuwiki:2025-05-14b:*:*:*:*:*:*:*
First Time Dokuwiki dokuwiki
Dokuwiki

08 Apr 2026, 19:25

Type Values Removed Values Added
References
  • () https://github.com/dokuwiki/dokuwiki/releases/tag/release-2025-05-14b -
Summary (en) An issue in Dokuwiki v.2025-05-14b 'Librarian' allows a remote attacker to cause a denial of service via the media_upload_xhr() function in the media.php file (en) An issue in Dokuwiki v.2025-05-14b "Librarian" [56.2] allows a remote attacker to cause a denial of service via the media_upload_xhr() function in the media.php file

08 Apr 2026, 08:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 4.3
CWE CWE-770

03 Apr 2026, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-400

03 Apr 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 15:16

Updated : 2026-04-09 00:16


NVD link : CVE-2026-26477

Mitre link : CVE-2026-26477

CVE.ORG link : CVE-2026-26477


JSON object : View

Products Affected

dokuwiki

  • dokuwiki
CWE
CWE-770

Allocation of Resources Without Limits or Throttling

CWE-400

Uncontrolled Resource Consumption