Simon Urli
46 exploits
Active since May 2021
XWiki <12.10.4,13.2RC0 - Info Disclosure
CVSS 7.5
XWiki 2.3-12.6.6 - Authenticated Path Traversal via Velocity Script File API
CVSS 7.5
XWiki 6.0.1-14.10.5 - Stored Cross-Site Scripting via Delete Template URL Parameter
CVSS 9.6
XWiki Platform 12.9-14.4.8 - Authenticated Eval Injection via First Name Field
CVSS 9.9
XWiki 6.0.1-14.10.5 - Stored Cross-Site Scripting via Delete Template URL Parameter
CVSS 9.6
XWiki Platform 5.0-rc-1-14.10.18 - Authenticated Exposure of Sensitive Information via History Diff Feature
CVSS 6.8
XWiki Platform 5.0-rc-1-14.10.18 - Authenticated Exposure of Sensitive Information via History Diff Feature
CVSS 6.8
XWiki REST API - Private Pages Disclosure
CVSS 5.3
XWiki 11.6-11.10.12 - Improper Authorization via Email Verification Activation Link
CVSS 8.8
XWiki 3.0.1-12.6.6 - Unauthenticated Remote Code Execution via Dashboard Gadget Title
CVSS 8.8
XWiki Platform <12.10.5, 13.0-13.1 - CSRF
CVSS 5.7
XWiki Platform <13.1-13.1 - Info Disclosure
CVSS 5.3
XWiki <12.10.4,13.2RC0 - Info Disclosure
CVSS 7.5
XWiki < 12.10.6 and 12.10.7 - URL Redirection to Untrusted Site via xredirect Parameter
CVSS 4.7
XWiki < 12.10.9, 13.5RC1-13.6RC1 - Unauthenticated User Enumeration via Password Reset Form
CVSS 5.3
XWiki Platform < 12.10.10, 12.10.11, 13.4.7, 13.10.3 - Cross-Site Scripting via xredirect Hidden Field
CVSS 7.4
XWiki Platform Old Core <14.3-rc-1 - Privilege Escalation
CVSS 8.1
XWiki Platform <13.10.5-14.3 - CSRF
CVSS 4.3
XWiki Platform 3.2-13.10.6 - Cross-Site Request Forgery in Tag Management
CVSS 7.4
XWiki 11.7-13.10.6, 14.0.0-14.4.1 - Missing Authorization in User#setDisabledStatus
CVSS 4.9
XWiki 12.4-13.10.6 - Unauthenticated Missing Authorization in User Profile UI
CVSS 7.5
XWiki 13.1-13.10.8 - Plaintext Password Storage in Forgot Password Feature
CVSS 6.2
XWiki 6.0-13.10.9 - Open Redirect via URL Scheme Omission
CVSS 4.7
XWiki 3.0-14.8 - Authenticated Stored Cross-Site Scripting via JavaScript or StyleSheet XObject
CVSS 9.0
XWiki < 13.10.11 - Unauthorized Deleted Document Access
CVSS 7.5