Simon Urli
46 exploits
Active since May 2021
XWiki 13.10.8-13.10.10 - Authenticated Cross-Site Scripting via Endpoint URL Injection
CVSS 5.4
XWiki 14.4.1-14.4.6 and 14.5-14.9 - Privilege Escalation via Document Script API
CVSS 9.1
XWiki < 13.10.11 - Authenticated Remote Code Execution via Attachment Selector Property Field
CVSS 9.0
XWiki Platform < 14.10.4 - Open Redirect via URL Parameter Manipulation
CVSS 4.7
XWiki 6.0.1-14.10.5 - Stored Cross-Site Scripting via Delete Template URL Parameter
CVSS 9.6
XWiki Platform < 14.10.6 - Cross-Site Scripting via Delete Attachment Action
CVSS 8.4
XWiki 9.4-14.10.4 - Stored Cross-Site Scripting via Restore Template URL Parameter
CVSS 9.6
XWiki 3.5-14.10.4 - Stored Cross-Site Scripting via Deletespace Template
CVSS 9.6
XWiki 3.0-14.10.4 - Cross-Site Scripting via Resubmit Template URL Parameter
CVSS 9.6
XWiki 6.2.1-14.10.4 - Stored Cross-Site Scripting via DeleteApplication Page
CVSS 9.6
XWiki 6.2-14.10.4 - Stored Cross-Site Scripting via Preview Actions Template
CVSS 9.6
Change Request 0.11-1.9.1 - Unauthenticated Remote Code Execution via Change Request Title
CVSS 10.0
XWiki Change Request < 1.10 - Authenticated Password Hash Exposure via Change Request Export
CVSS 7.7
XWiki < 14.10.17, 15.0-rc-1-15.5.3 - Privilege Escalation via Rollback Action
CVSS 8.0
XWiki Platform 5.0-rc-1-14.10.18 - Authenticated Exposure of Sensitive Information via History Diff Feature
CVSS 6.8
XWiki Platform <14.10.21 - Info Disclosure
CVSS 6.5
XWiki 13.2-14.10.20 Unauthorized Access via NotificationFilterPreferenceLivetableResults
CVSS 5.3
XWiki Platform <15.10.14, 16.4.6, 16.10.0-rc-1 - Info Disclosure
CVSS 7.5
XWiki REST API - Private Pages Disclosure
CVSS 5.3
XWiki Platform <15.10.15, <16.4.6, <16.10.0 - Info Disclosure
CVSS 9.8
XWiki 7.4.5-16.4.6, 16.10.0-16.10.3, 17.0.0-rc-1-17.0.0 - Incorrect Privilege Assignment via Page Link Renaming
CVSS 8.0