Michael Hamann
102 exploits
Active since Sep 2022
XWiki 15.9-16.4.6 - Insufficient UI Warning of Dangerous Operations in Macro Parameter Analysis
CVSS 8.0
XWiki 15.9-16.4.6 - Insufficient UI Warning of Dangerous Operations in Macro Parameter Analysis
CVSS 8.0
XWiki's REST APIs can list all pages/spaces, leading to unavailability
CVSS 8.2
XWiki has Reflected Cross-Site Scripting (XSS) in its page history compare functionality
CVSS 6.1
XWiki Platform affected by remote code execution with script right through unprotected Velocity scripting API
CVSS 9.8
XWiki Platform Old Core <14.2-13.10.4 - Auth Bypass
CVSS 7.5
XWiki Platform Web Templates <14.2 & <13.10.4 - Auth Bypass
CVSS 8.5
XWiki Platform Wiki UI Main Wiki <13.10.6-14.4 - Code Injection
CVSS 9.9
XWiki Platform <14.4 - Code Injection
CVSS 9.9
xwiki-platform-icon-ui - Eval Injection
CVSS 9.9
XWiki Platform < 13.10.8 - Authenticated Remote Code Execution via Menu Macro Injection
CVSS 9.9
CKEditor Integration UI <1.64.3 - CSRF
CVSS 9.0
XWiki 1.8-14.5 - Stored Cross-Site Scripting via RSS Macro Content Parameter
CVSS 9.0
XWiki 1.9-13.10.9 - Stored Cross-Site Scripting via Livetable Macro Column Names
CVSS 8.9
XWiki <13.10.11 - Code Execution via Legacy Notification Activity Macro
CVSS 9.9
XWiki < 13.10.11 - Authenticated Remote Code Execution via Notification Preferences Macro
CVSS 9.9
XWiki < 14.10.2 - Authenticated Remote Code Execution via User Translation Override
CVSS 9.9
XWiki < 13.10.11 - Authenticated Remote Code Execution via Document Edit
CVSS 9.9
XWiki < 13.10.11 - Authenticated JavaScript Injection via App Within Minutes Space Admin Right
CVSS 7.7
XWiki < 13.10.11 - Authenticated Remote Code Execution via Script Macro Injection
CVSS 9.9
XWiki Platform 2.2.1-14.4.7 - Stored Cross-Site Scripting via DisplayContent or RenderContent Template
CVSS 9.0
XWiki 2.0-14.10.7 - Incomplete Cleanup of Vulnerable Document Revisions
CVSS 9.9
XWiki 9.6-14.10.5 - Authenticated Remote Code Execution via User Profile Script Macros
CVSS 9.9
XWiki 6.2-14.10.5 - Remote Code Execution via Icon Set Injection
CVSS 9.9
XWiki 1.8-14.10.8 - Cross-Site Request Forgery via REST API
CVSS 9.6