org.xwiki.platform

231 tracked vulnerabilities.

CVE-2024-43401 CRITICAL
XWiki Platform < 15.10-rc-1 - Unauthenticated Privilege Escalation via WYSIWYG Editor Payload
Aug 19, 2024
CVSS 9.0
EPSS 0.01
CVE-2024-43400 CRITICAL
XWiki < 14.10.21 - Stored Cross-Site Scripting via Crafted URL
Aug 19, 2024
CVSS 9.0
EPSS 0.07
CVE-2024-41947 CRITICAL
XWiki 11.8-15.10.7 - Stored Cross-Site Scripting via Edit Conflict
Jul 31, 2024
CVSS 9.0
EPSS 0.13
CVE-2024-37901 CRITICAL
XWiki 9.2-14.10.20 - Authenticated Remote Code Execution via SearchSuggestClass Instances
Jul 31, 2024
CVSS 9.9
EPSS 0.10
CVE-2024-37900 MEDIUM
XWiki 4.2-14.10.21 - Stored Cross-Site Scripting via Malicious Attachment Filename
Jul 31, 2024
CVSS 6.4
EPSS 0.05
CVE-2024-37898 MEDIUM
XWiki Platform 13.10.4-14.0 and 13.10.4-14.10.21 - Missing Authorization in Page Deletion
Jul 31, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-38369 CRITICAL
XWiki Platform - Privilege Escalation
Jun 24, 2024
CVSS 9.9
EPSS 0.01
CVE-2024-37899 CRITICAL
XWiki Platform 13.10.3-14.10.20 - Authenticated Remote Code Execution via User Profile Disabling
Jun 20, 2024
CVSS 9.0
EPSS 0.14
CVE-2024-31997 CRITICAL
XWiki Platform <4.10.19, 15.5.4, 15.10-rc-1 - RCE
Apr 10, 2024
CVSS 9.9
EPSS 0.54
CVE-2024-31988 CRITICAL
XWiki Platform <4.10.19, 15.5.4, 15.10-rc-1 - RCE
Apr 10, 2024
CVSS 9.6
EPSS 0.07
CVE-2024-31987 CRITICAL
XWiki Platform <6.4-4.10.19, 15.5.4, 15.10-rc-1 - RCE
Apr 10, 2024
CVSS 9.9
EPSS 0.24
CVE-2024-31986 CRITICAL
XWiki Platform <4.10.19-15.10-rc-1 - RCE
Apr 10, 2024
CVSS 9.0
EPSS 0.08
CVE-2024-31985 MEDIUM
XWiki Platform <4.10.20-15.10-rc-1 - Info Disclosure
Apr 10, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-31984 CRITICAL
XWiki Platform <4.10.20, 15.5.4, 15.10-rc-1 - RCE
Apr 10, 2024
CVSS 9.9
EPSS 0.60
CVE-2024-31983 CRITICAL
XWiki Platform <4.10.20, 15.5.4, 15.10-rc-1 - RCE
Apr 10, 2024
CVSS 9.9
EPSS 0.23
CVE-2024-31982 CRITICAL NUCLEI
XWiki Platform <4.10.20,15.5.4,15.10-rc-1 - RCE
Apr 10, 2024
CVSS 10.0
EPSS 0.94
CVE-2024-31981 CRITICAL
XWiki Platform <4.10.20, 15.5.4, 15.10-rc-1 - RCE
Apr 10, 2024
CVSS 9.9
EPSS 0.24
CVE-2024-31465 CRITICAL
XWiki 5.0-rc-1-14.10.19 - Authenticated Remote Code Execution via XWiki.SearchSuggestSourceClass Object Injection
Apr 10, 2024
CVSS 9.9
EPSS 0.35
CVE-2024-31464 MEDIUM
XWiki Platform 5.0-rc-1-14.10.18 - Authenticated Exposure of Sensitive Information via History Diff Feature
Apr 10, 2024
CVSS 6.8
EPSS 0.00
CVE-2024-21651 HIGH
XWiki 14.10-14.10.17 - Denial of Service via Malformed TAR File Attachment
Jan 09, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-21648 HIGH
XWiki < 14.10.17, 15.0-rc-1-15.5.3 - Privilege Escalation via Rollback Action
Jan 09, 2024
CVSS 8.0
EPSS 0.00
CVE-2024-21650 CRITICAL NUCLEI
XWiki < 4.10.20 - Remote code execution
Jan 08, 2024
CVSS 10.0
EPSS 0.93
CVE-2023-50732 HIGH
XWiki 8.3-14.10.6 - Unauthenticated Velocity Script Execution via Document Tree
Dec 21, 2023
CVSS 8.3
EPSS 0.01
CVE-2023-50723 CRITICAL
XWiki Platform 2.3-14.10.5 - Authenticated Remote Code Execution via Administration Interface
Dec 15, 2023
CVSS 9.9
EPSS 0.05
CVE-2023-50722 CRITICAL
XWiki Platform 2.3-14.10.4 - Unauthenticated Remote Code Execution via Configurable Admin Section URL Parameter
Dec 15, 2023
CVSS 9.6
EPSS 0.03