Skip to main content

Vendor archive

xwiki CVEs

Beta · best-effort

282 CVEs tagged to vendor xwiki129 Critical, 76 High, 69 Medium, 8 Low, 0 Unrated.

CVE-2023-40573

Published Aug 24, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki supports scheduled jobs that contain Groovy scripts. Currently, the…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-40572

Published Aug 24, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The create action is vulnerable to a CSRF attack, allowing script and thus…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-40177

Published Aug 23, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can use the content field of their user profile page t…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-40176

Published Aug 23, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can exploit a stored XSS through their user profile by…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-37914

Published Aug 17, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can view `Invitation.WebHome` can execute arbitrary script ma…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-37462

Published Jul 14, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode.XWikiSkinsSheet` leads to an…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-37277

Published Jul 10, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The REST API allows executing all actions via POST requests and accepts `t…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-36477

Published Jun 30, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights can edit all pages in the `CKEditor' space. This…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-36470

Published Jun 29, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By either creating a new or editing an existing document with an icon set,…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-36469

Published Jun 29, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile and notification settings can…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-36468

Published Jun 29, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an XWiki installation is upgraded and that upgrade contains a fix for…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-36471

Published Jun 29, 2023

Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki since version 14.6RC1 allowed form and input HTML tags. In…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-35162

Published Jun 23, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascrip…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-35161

Published Jun 23, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascrip…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-35160

Published Jun 23, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascrip…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-35159

Published Jun 23, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascrip…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-35158

Published Jun 23, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascrip…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-35157

Published Jun 23, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to perform an XSS by forging a request to a delete attachmen…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-35156

Published Jun 23, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascrip…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-35155

Published Jun 23, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascrip…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-35153

Published Jun 23, 2023

XWiki Platform is a generic wiki platform. Starting in version 5.4.4 and prior to versions 14.4.8, 14.10.4, and 15.0, a stored cross-site scripting vulnerability can be exploited…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-35152

Published Jun 23, 2023

XWiki Platform is a generic wiki platform. Starting in version 12.9-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.1, any logged in user can add dangerous content in their fir…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-35151

Published Jun 23, 2023

XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obf…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-35150

Published Jun 23, 2023

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to versions 14.4.8, 14.10.4, and 15.…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-34467

Published Jun 23, 2023

XWiki Platform is a generic wiki platform. Starting in version 3.5-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, the mail obfuscation configuration was not ful…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 126-150 of 282 CVEsPage 6 of 12