Michael Hamann
75 exploits
Active since Sep 2022
XWiki's REST APIs can list all pages/spaces, leading to unavailability
CVSS 8.2
XWiki has Reflected Cross-Site Scripting (XSS) in its page history compare functionality
CVSS 6.1
XWiki Platform affected by remote code execution with script right through unprotected Velocity scripting API
CVSS 9.8
XWiki Platform Old Core <14.2-13.10.4 - Auth Bypass
CVSS 7.5
XWiki Platform Web Templates <14.2 & <13.10.4 - Auth Bypass
CVSS 8.5
XWiki Platform Wiki UI Main Wiki <13.10.6-14.4 - Code Injection
CVSS 9.9
XWiki Platform <14.4 - Code Injection
CVSS 9.9
xwiki-platform-icon-ui - Eval Injection
CVSS 9.9
XWiki Platform - RCE
CVSS 9.9
CKEditor Integration UI <1.64.3 - CSRF
CVSS 9.0
XWiki Commons - XSS
CVSS 9.0
XWiki Commons - XSS
CVSS 8.9
XWiki - RCE
CVSS 9.9
XWiki Commons - RCE
CVSS 9.9
Xwiki < 14.10.2 - Injection
CVSS 9.9
Xwiki < 13.10.11 - Injection
CVSS 9.9
Xwiki < 13.10.11 - XSS
CVSS 7.7
Xwiki < 13.10.11 - Injection
CVSS 9.9
Xwiki < 14.4.8 - XSS
CVSS 9.0
XWiki Platform - Info Disclosure
CVSS 9.9
XWiki Platform - RCE
CVSS 9.9
XWiki Platform - RCE
CVSS 9.9
Xwiki < 14.10.8 - CSRF
CVSS 9.6
Xwiki < 14.4.8 - Injection
CVSS 9.9
Xwiki < 14.10.8 - Code Injection
CVSS 9.9