Michael Hamann
102 exploits
Active since Sep 2022
XWiki Platform Old Core <14.2-13.10.4 - Auth Bypass
CVSS 7.5
XWiki Platform < 13.10.8 - Authenticated Remote Code Execution via Menu Macro Injection
CVSS 9.9
XWiki 5.0-14.4 and xwiki-commons-xml 4.2-milestone-1-14.5 - Stored Cross-Site Scripting via HTML Cleaner Restricted Mode
CVSS 9.0
XWiki 9.6-14.10.5 - Authenticated Remote Code Execution via User Profile Script Macros
CVSS 9.9
XWiki 6.2-14.10.5 - Remote Code Execution via Icon Set Injection
CVSS 9.9
XWiki Platform 2.3-14.10.5 - Authenticated Remote Code Execution via Administration Interface
CVSS 9.9
XWiki 5.0-14.4 and xwiki-commons-xml 4.2-milestone-1-14.5 - Stored Cross-Site Scripting via HTML Cleaner Restricted Mode
CVSS 9.0
XWiki Commons 4.2-milestone-1-14.9 - Cross-Site Scripting via Invalid HTML Comments
CVSS 9.0
org.xwiki.commons:xwiki-commons-xml - XSS
CVSS 9.0
XWiki Platform < 14.6-rc-1 - Cross-Site Scripting via HTML Attribute Injection
CVSS 9.0
XWiki 9.6-14.10.5 - Authenticated Remote Code Execution via User Profile Script Macros
CVSS 9.9
XWiki 6.2-14.10.5 - Remote Code Execution via Icon Set Injection
CVSS 9.9
XWiki Commons 14.6-14.10.5 - Remote Code Execution via HTML Sanitizer Bypass
CVSS 9.0
XWiki Rendering 14.6-14.10.3 - Cross-Site Scripting via Invalid Attribute Names
CVSS 9.0
XWiki Platform 2.3-14.10.5 - Authenticated Remote Code Execution via Administration Interface
CVSS 9.9
XWiki Platform < 14.10.14 - Unauthenticated Remote Code Execution via Section URL Parameter
CVSS 10.0
XWiki Admin Tools 4.4-4.5.1 - Cross-Site Request Forgery via Shell Command Execution
CVSS 9.6
XWiki Platform 2.3-14.10.5 - Authenticated Remote Code Execution via Administration Interface
CVSS 9.9
XWiki Platform 13.10.4-14.0 and 13.10.4-14.10.21 - Missing Authorization in Page Deletion
CVSS 4.3
XWiki Platform <4.10.19, 15.5.4, 15.10-rc-1 - RCE
CVSS 9.9
XWiki Platform 13.10.4-14.0 and 13.10.4-14.10.21 - Missing Authorization in Page Deletion
CVSS 4.3
XWiki Platform <4.10.19, 15.5.4, 15.10-rc-1 - RCE
CVSS 9.9
XWiki Platform 13.10.4-14.0 and 13.10.4-14.10.21 - Missing Authorization in Page Deletion
CVSS 4.3
XWiki 1.8-15.10.8 - Unauthenticated Exposure of Private Personal Information via REST API
CVSS 5.3
XWiki 15.9-16.4.6 - Insufficient UI Warning of Dangerous Operations in Macro Parameter Analysis
CVSS 8.0