org.xwiki.platform

231 tracked vulnerabilities.

CVE-2023-37914 CRITICAL
XWiki 2.5-14.4.8 - Authenticated Remote Code Execution via Script Macro Injection in Invitation.WebHome
Aug 17, 2023
CVSS 9.9
EPSS 0.04
CVE-2023-37462 CRITICAL NUCLEI
XWiki 7.0-14.4.8 - Remote Code Execution via SkinsCode.XWikiSkinsSheet Injection
Jul 14, 2023
CVSS 9.9
EPSS 0.90
CVE-2023-37277 CRITICAL
XWiki 1.8-14.10.8 - Cross-Site Request Forgery via REST API
Jul 10, 2023
CVSS 9.6
EPSS 0.03
CVE-2023-36477 CRITICAL
XWiki Platform 14.6-14.10.5 & CKEditor 1.9-1.64.8 - Authenticated XSS via CKEditor Config
Jun 30, 2023
CVSS 9.0
EPSS 0.03
CVE-2023-36470 CRITICAL
XWiki 6.2-14.10.5 - Remote Code Execution via Icon Set Injection
Jun 29, 2023
CVSS 9.9
EPSS 0.13
CVE-2023-36469 CRITICAL
XWiki 9.6-14.10.5 - Authenticated Remote Code Execution via User Profile Script Macros
Jun 29, 2023
CVSS 9.9
EPSS 0.40
CVE-2023-36468 CRITICAL
XWiki 2.0-14.10.7 - Incomplete Cleanup of Vulnerable Document Revisions
Jun 29, 2023
CVSS 9.9
EPSS 0.09
CVE-2023-35162 CRITICAL NUCLEI
XWiki 6.2-14.10.4 - Stored Cross-Site Scripting via Preview Actions Template
Jun 23, 2023
CVSS 9.6
EPSS 0.16
CVE-2023-35161 CRITICAL NUCLEI
XWiki 6.2.1-14.10.4 - Stored Cross-Site Scripting via DeleteApplication Page
Jun 23, 2023
CVSS 9.6
EPSS 0.16
CVE-2023-35160 CRITICAL NUCLEI
XWiki 3.0-14.10.4 - Cross-Site Scripting via Resubmit Template URL Parameter
Jun 23, 2023
CVSS 9.6
EPSS 0.12
CVE-2023-35159 CRITICAL NUCLEI
XWiki 3.5-14.10.4 - Stored Cross-Site Scripting via Deletespace Template
Jun 23, 2023
CVSS 9.6
EPSS 0.04
CVE-2023-35158 CRITICAL NUCLEI
XWiki 9.4-14.10.4 - Stored Cross-Site Scripting via Restore Template URL Parameter
Jun 23, 2023
CVSS 9.6
EPSS 0.10
CVE-2023-35157 HIGH
XWiki Platform < 14.10.6 - Cross-Site Scripting via Delete Attachment Action
Jun 23, 2023
CVSS 8.4
EPSS 0.01
CVE-2023-35156 CRITICAL NUCLEI
XWiki 6.0.1-14.10.5 - Stored Cross-Site Scripting via Delete Template URL Parameter
Jun 23, 2023
CVSS 9.6
EPSS 0.10
CVE-2023-35155 HIGH NUCLEI
XWiki < 14.4.8 - Stored Cross-Site Scripting via Share Page URL Parameter
Jun 23, 2023
CVSS 8.8
EPSS 0.47
CVE-2023-35153 CRITICAL
XWiki 5.4.4-14.4.7 - Stored Cross-Site Scripting via AppWithinMinutes.FormFieldCategoryClass Page Title
Jun 23, 2023
CVSS 9.0
EPSS 0.02
CVE-2023-35152 CRITICAL
XWiki Platform 12.9-14.4.8 - Authenticated Eval Injection via First Name Field
Jun 23, 2023
CVSS 9.9
EPSS 0.02
CVE-2023-35151 HIGH
XWiki 7.3-milestone-1-14.4.8 - Unauthenticated Exposure of Obfuscated Passwords via REST Endpoint
Jun 23, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-35150 CRITICAL
XWiki Platform 2.40m-2-14.4.8, 14.10.4, 15.0 - Remote Code Execution via Crafted URL Payload
Jun 23, 2023
CVSS 9.9
EPSS 0.35
CVE-2023-34467 HIGH
XWiki Platform <14.4.8-15.0-rc-1 - Info Disclosure
Jun 23, 2023
CVSS 7.5
EPSS 0.02
CVE-2023-34466 MEDIUM
XWiki 5.0.1-14.4.7 - Unauthorized Information Disclosure via Tags API
Jun 23, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-34465 CRITICAL
XWiki 11.8-rc-1-14.4.7 - Authenticated Privilege Escalation via Mail.MailConfig Page
Jun 23, 2023
CVSS 9.9
EPSS 0.01
CVE-2023-34464 CRITICAL
XWiki Platform 2.2.1-14.4.7 - Stored Cross-Site Scripting via DisplayContent or RenderContent Template
Jun 23, 2023
CVSS 9.0
EPSS 0.01
CVE-2023-35166 CRITICAL
XWiki 8.1-14.10.5 - Incorrect Authorization via Tip UI Extension
Jun 20, 2023
CVSS 9.9
EPSS 0.24
CVE-2023-32068 MEDIUM NUCLEI
XWiki Platform < 14.10.4 - Open Redirect via URL Parameter Manipulation
May 15, 2023
CVSS 4.7
EPSS 0.42