Michael Hamann
102 exploits
Active since Sep 2022
XWiki Platform 13.10.4-14.0 and 13.10.4-14.10.21 - Missing Authorization in Page Deletion
CVSS 4.3
XWiki 1.8-15.10.8 - Unauthenticated Exposure of Private Personal Information via REST API
CVSS 5.3
XWiki Platform - Cross-Site Scripting
CVSS 6.1
XWiki WYSIWYG API - Open Redirect
CVSS 6.1
XWiki 4.5.1-15.10.12, 16.0.0-rc-1-16.4.3, 16.5.0-rc-1-16.8.0-rc-1 - Incorrect Authorization in Solr Script Service
CVSS 3.8
XWiki 6.1-15.10.11, 16.0.0-16.4.2, 16.5.0-16.7.0 - Authenticated Cache Clearing via LESS Compiler
CVSS 2.7
XWiki 15.9-15.10.12, 16.0.0-16.4.3, 16.5.0-16.8.0-rc-1 - Missing Authorization for Programming Rights
CVSS 9.0
XWiki 15.9-15.10.7 and 16.0.0-16.1.0 - Privilege Escalation via TextArea Default Content Type
CVSS 9.0
XWiki 16.10.0-16.10.3 - Authenticated Remote Code Execution via Required Rights Bypass
CVSS 8.8
XWiki Wiki Macro Parameters - Programming Rights Code Execution
CVSS 8.8
XWiki 15.9-16.4.6 - Insufficient UI Warning of Dangerous Operations in Macro Parameter Analysis
CVSS 8.0
XWiki < 15.10.16 - Insufficient UI Warning of Dangerous Operations in Notification Email Renderer
CVSS 3.5
XWiki <16.4.6, 16.5.0-rc-1, 16.10.2, 17.0.0-rc-1 - Info Disclosure
CVSS 7.5
XWiki - Code Injection via XClass Definition
CVSS 8.0
XWiki 7.3-16.4.6 - Authenticated Remote Code Execution via App Within Minutes Application Edit
CVSS 8.8
XWiki 15.9-15.10.15 - Stored Cross-Site Scripting via Notification Displayer Object
CVSS 8.0
XWiki 5.4.5-14.10 - Stored Cross-Site Scripting via Raw Block HTML Injection
CVSS 9.0
XWiki Rendering <13.10.11-14.4.7-14.10 - RCE
CVSS 9.9
XWiki Platform <17.1.0 - Info Disclosure
CVSS 6.5
XWiki Platform <17.1.0 - Info Disclosure
CVSS 6.5
XWiki <9.14 - Remote Code Execution
XWiki Full Calendar Macro < 2.4.6 - Unauthenticated Exposure of Sensitive Information via Calendar.JSONService
CVSS 5.3
XWiki Platform <16.10.9, <17.0.0-rc-1 to <17.4.1 - XSS
CVSS 6.1
XWiki < 16.10.11 - Denial of Service via Unrestricted REST API Item Requests
CVSS 7.5
XWiki Rendering < 16.10.10, 17.0.0-rc-1-17.4.2, 17.5.0-rc-1-17.5.0 - Remote Code Execution via HTML Macro Injection
CVSS 8.8