Manuel Leduc
35 exploits
Active since Sep 2022
XWiki Platform <13.10.6, <14.4 - RCE
CVSS 8.9
XWiki 12.10-13.10.9 - Stored Cross-Site Scripting via Live Data Macro
CVSS 8.9
XWiki 11.8-rc-1-14.4.7 - Authenticated Privilege Escalation via Mail.MailConfig Page
CVSS 9.9
XWiki Platform <14.10.9, <15.3-rc-1 - Info Disclosure
CVSS 4.3
XWiki < 14.10.21 - Stored Cross-Site Scripting via Crafted URL
CVSS 9.0
XWiki Platform Attachment UI 14.0-rc-1-14.3 - Stored Cross-Site Scripting via Attachment Name
CVSS 8.9
XWiki Platform <13.10.6, <14.4 - RCE
CVSS 8.9
XWiki 12.10.11-13.10.8 - Unauthenticated Exposure of Sensitive Information via Livetable Queries
CVSS 5.3
XWiki 8.1-13.10.7 - Unauthorized Exposure of Private Information via Modifications REST Endpoint
CVSS 5.3
XWiki Platform <14.7-rc-1, <13.4.4, <13.10.9 - Info Disclosure
CVSS 7.5
XWiki Platform <13.10.10, <14.9-rc-1, <14.4.6 - Code Injection
CVSS 10.0
XWiki Platform <14.3-rc-1 - Info Disclosure
CVSS 6.6
XWiki Platform <6.0 - Info Disclosure
CVSS 6.5
XWiki 12.10-13.10.9 - Stored Cross-Site Scripting via Live Data Macro
CVSS 8.9
XWiki < 13.10.11 - Authenticated Remote Code Execution via Improper WikiId Parameter Escaping
CVSS 9.9
XWiki 14.0-14.4.7 - Authenticated Remote Code Execution via Insufficient Escaping in Included Documents Edit Panel
CVSS 9.9
XWiki Platform < 13.10.11 - Authenticated Remote Code Execution via URL Expression Injection
CVSS 9.0
XWiki < 13.10.11 - Authenticated Remote Code Execution via IncludedDocuments Panel
CVSS 9.9
XWiki < 13.10.11 - Authenticated Remote Code Execution via DocumentTree Macro Parameter Injection
CVSS 9.9
XWiki 1.7-13.10.10 - Authenticated Remote Code Execution via Section ID Injection in AdminFieldsDisplaySheet
CVSS 9.9
XWiki < 13.10.11 - Authenticated Remote Code Execution via Improper Escaping in Attachment Handling
CVSS 9.9
XWiki < 13.10.11 - Authenticated Remote Code Execution via AttachmentSelector Cancel Button
CVSS 9.9
XWiki < 13.10.11 - Authenticated Remote Code Execution via Invitation.InvitationCommon Page
CVSS 9.9
XWiki < 13.10.11 - Authenticated Remote Code Execution via Macro.VFSTreeMacro
CVSS 8.4
XWiki < 14.4.8 - Remote Code Execution via Crafted Page Name
CVSS 9.9