Michael Hamann
102 exploits
Active since Sep 2022
XWiki 7.0-14.4.8 - Remote Code Execution via SkinsCode.XWikiSkinsSheet Injection
CVSS 9.9
XWiki 5.1-14.10.7 - Authenticated Remote Code Execution via User Profile Script Macro Injection
CVSS 9.9
XWiki 14.0-14.4.7 - Missing Authorization for Attachment Move
CVSS 8.1
XWiki 9.4-14.10.7 - Unauthorized Deleted Document Content Exposure via Diff Feature
CVSS 6.5
XWiki Rendering < 14.10.6 - Privilege Escalation via Footnote Macro Context Switching
CVSS 9.9
XWiki 3.5-14.10.8 - Path Traversal and Arbitrary File Write via Office Converter
CVSS 9.9
XWiki < 14.10.9 - Cross-Site Request Forgery via Create Action
CVSS 9.0
XWiki < 14.10.9 - Remote Code Execution via Scheduled Job Script Injection
CVSS 9.0
XWiki 7.2-14.10.9 - Unauthenticated Velocity Code Execution via XClass TextArea Property
CVSS 6.3
XWiki Platform 3.1.1-13.3 - Stored Cross-Site Scripting via Template Provider
CVSS 9.0
XWiki Platform 7.2-milestone-2-14.10.12 - Remote Code Execution via Page Creation Title Parameter
CVSS 9.0
XWiki 12.0-14.10.12 - Reflected Cross-Site Scripting in Page Creation Form
CVSS 9.6
XWiki Platform < 14.10.12 - Stored XSS via Document Creation Error Message
CVSS 9.0
XWiki Platform < 14.10.14 - Unauthenticated Remote Code Execution via Section URL Parameter
CVSS 10.0
XWiki 9.7-14.10.13 - Reflected Cross-Site Scripting via Rev Parameter
CVSS 9.6
XWiki 11.10.1-14.10.14 - Cookie Theft and Server-Side Request Forgery via Diff Image Embedding
CVSS 9.0
XWiki Platform 6.3-milestone-2-14.10.15 - Unauthenticated Information Disclosure via Solr Search Suggestion Provider
CVSS 7.5
XWiki Admin Tools Application < 4.5.1 - Cross-Site Request Forgery via Query on XWiki Tool
CVSS 8.8
XWiki Platform 7.2-milestone-2-14.10.14 - Unauthenticated Exposure of Sensitive Information via Solr Search
CVSS 7.5
XWiki Platform < 14.10.15 - Unauthenticated Exposure of Sensitive Information via Solr Search
CVSS 5.3
XWiki Platform 4.5-14.10.5 - Remote Code Execution via Search UI Extension Injection
CVSS 9.9
XWiki Platform 2.3-14.10.4 - Unauthenticated Remote Code Execution via Configurable Admin Section URL Parameter
CVSS 9.6
XWiki Platform 2.3-14.10.5 - Authenticated Remote Code Execution via Administration Interface
CVSS 9.9
XWiki < 4.10.20 - Remote code execution
CVSS 10.0
XWiki Platform <4.10.19, 15.5.4, 15.10-rc-1 - RCE
CVSS 9.9