org.xwiki.platform

231 tracked vulnerabilities.

CVE-2023-32070 CRITICAL
XWiki Platform < 14.6-rc-1 - Cross-Site Scripting via HTML Attribute Injection
May 10, 2023
CVSS 9.0
EPSS 0.22
CVE-2023-32071 CRITICAL
XWiki Platform <2.2-14.4.8, <14.10.4, <15.0-rc-1 - XSS
May 09, 2023
CVSS 9.0
EPSS 0.34
CVE-2023-32069 CRITICAL
XWiki 3.3-milestone-2-14.10.3 - Incorrect Authorization
May 09, 2023
CVSS 9.9
EPSS 0.21
CVE-2023-29527 CRITICAL
XWiki 7.4.4-14.10.2 - Unauthenticated Remote Code Execution via Groovy Script Injection
Apr 19, 2023
CVSS 9.9
EPSS 0.10
CVE-2023-29526 CRITICAL
XWiki Platform 10.11.1-13.10.11 - Remote Code Execution via Async and Display Macros
Apr 19, 2023
CVSS 9.9
EPSS 0.23
CVE-2023-29525 CRITICAL
XWiki < 14.4.8, 12.6.1-13.10.11, 14.6-rc-1-14.10.3 - Code Injection via LegacyNotificationAdministration since Parameter
Apr 19, 2023
CVSS 9.9
EPSS 0.54
CVE-2023-29524 CRITICAL
XWiki < 14.10.3 - Authenticated Remote Code Execution via Scheduler Job Script Injection
Apr 19, 2023
CVSS 9.9
EPSS 0.48
CVE-2023-29523 CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via Script Macro Injection
Apr 19, 2023
CVSS 9.9
EPSS 0.11
CVE-2023-29522 CRITICAL
XWiki < 14.4.8 - Remote Code Execution via Crafted Page Name
Apr 19, 2023
CVSS 9.9
EPSS 0.36
CVE-2023-29521 HIGH
XWiki < 13.10.11 - Authenticated Remote Code Execution via Macro.VFSTreeMacro
Apr 19, 2023
CVSS 8.4
EPSS 0.15
CVE-2023-29520 MEDIUM
XWiki < 13.10.11 - Denial of Service via Corrupted Translation Document
Apr 19, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-29519 CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via Attachment Selector Property Field
Apr 19, 2023
CVSS 9.0
EPSS 0.05
CVE-2023-29518 CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via Invitation.InvitationCommon Page
Apr 19, 2023
CVSS 9.9
EPSS 0.29
CVE-2023-29517 HIGH
XWiki < 13.10.11 - Unauthenticated Exposure of Sensitive Information via Office Document Viewer Macro
Apr 19, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-29516 CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via AttachmentSelector Cancel Button
Apr 19, 2023
CVSS 9.9
EPSS 0.27
CVE-2023-29515 HIGH
XWiki < 13.10.11 - Authenticated JavaScript Injection via App Within Minutes Space Admin Right
Apr 19, 2023
CVSS 7.7
EPSS 0.07
CVE-2023-29514 CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via Document Edit
Apr 19, 2023
CVSS 9.9
EPSS 0.30
CVE-2023-29513 MEDIUM
XWiki < 14.10.1 - Unauthenticated User Creation via Distribution First Admin User Endpoint
Apr 19, 2023
CVSS 5.0
EPSS 0.02
CVE-2023-29512 CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via Improper Escaping in Attachment Handling
Apr 19, 2023
CVSS 9.9
EPSS 0.29
CVE-2023-29510 CRITICAL
XWiki < 14.10.2 - Authenticated Remote Code Execution via User Translation Override
Apr 19, 2023
CVSS 9.9
EPSS 0.30
CVE-2023-29213 CRITICAL
XWiki Platform < 13.10.11 - Authenticated Remote Code Execution via URL Expression Injection
Apr 17, 2023
CVSS 9.0
EPSS 0.04
CVE-2023-30537 CRITICAL
XWiki 12.6.6-13.10.10 - Authenticated Remote Code Execution via FlamingoThemesCode.WebHome Style Property
Apr 16, 2023
CVSS 9.9
EPSS 0.29
CVE-2023-29511 CRITICAL
XWiki 1.7-13.10.10 - Authenticated Remote Code Execution via Section ID Injection in AdminFieldsDisplaySheet
Apr 16, 2023
CVSS 9.9
EPSS 0.29
CVE-2023-29509 CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via DocumentTree Macro Parameter Injection
Apr 16, 2023
CVSS 9.9
EPSS 0.36
CVE-2023-29508 HIGH
XWiki < 13.10.11 - Stored Cross-Site Scripting via Live Data Macro
Apr 16, 2023
CVSS 8.9
EPSS 0.04