org.xwiki.platform
231 tracked vulnerabilities.
CVE-2023-29507
CRITICAL
XWiki 14.4.1-14.4.6 and 14.5-14.9 - Privilege Escalation via Document Script API
Apr 16, 2023
CVSS 9.1
EPSS 0.10
CVE-2023-29506
MEDIUM
NUCLEI
XWiki 13.10.8-13.10.10 - Authenticated Cross-Site Scripting via Endpoint URL Injection
Apr 16, 2023
CVSS 5.4
EPSS 0.12
CVE-2023-29214
CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via IncludedDocuments Panel
Apr 16, 2023
CVSS 9.9
EPSS 0.06
CVE-2023-29212
CRITICAL
XWiki 14.0-14.4.7 - Authenticated Remote Code Execution via Insufficient Escaping in Included Documents Edit Panel
Apr 16, 2023
CVSS 9.9
EPSS 0.08
CVE-2023-29211
CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via Improper WikiId Parameter Escaping
Apr 16, 2023
CVSS 9.9
EPSS 0.08
CVE-2023-29210
CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via Notification Preferences Macro
Apr 15, 2023
CVSS 9.9
EPSS 0.06
CVE-2023-29209
CRITICAL
XWiki <13.10.11 - Code Execution via Legacy Notification Activity Macro
Apr 15, 2023
CVSS 9.9
EPSS 0.19
CVE-2023-29208
HIGH
XWiki < 13.10.11 - Unauthorized Deleted Document Access
Apr 15, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-29207
HIGH
XWiki 1.9-13.10.9 - Stored Cross-Site Scripting via Livetable Macro Column Names
Apr 15, 2023
CVSS 8.9
EPSS 0.18
CVE-2023-29206
CRITICAL
XWiki 3.0-14.8 - Authenticated Stored Cross-Site Scripting via JavaScript or StyleSheet XObject
Apr 15, 2023
CVSS 9.0
EPSS 0.04
CVE-2023-29205
CRITICAL
XWiki < 14.7 and xwiki-platform-rendering-xwiki < 14.8-rc-1 - Stored Cross-Site Scripting via HTML Macro
Apr 15, 2023
CVSS 9.9
EPSS 0.02
CVE-2023-29204
MEDIUM
NUCLEI
XWiki 6.0-13.10.9 - Open Redirect via URL Scheme Omission
Apr 15, 2023
CVSS 4.7
EPSS 0.01
CVE-2023-29203
LOW
XWiki 13.9-13.10.8 - Unauthorized Exposure of Private User Information via uorgsuggest.vm
Apr 15, 2023
CVSS 3.7
EPSS 0.00
CVE-2023-29202
CRITICAL
XWiki 1.8-14.5 - Stored Cross-Site Scripting via RSS Macro Content Parameter
Apr 15, 2023
CVSS 9.0
EPSS 0.11
CVE-2023-27480
HIGH
XWiki Platform < 13.10.11 - XML External Entity Injection via XAR Import
Mar 07, 2023
CVSS 7.7
EPSS 0.00
CVE-2023-27479
CRITICAL
XWiki 6.3-13.10.10 - Authenticated Remote Code Execution via UIX Parameter Injection
Mar 07, 2023
CVSS 9.9
EPSS 0.15
CVE-2023-26476
HIGH
XWiki Platform <14.7-rc-1, <13.4.4, <13.10.9 - Info Disclosure
Mar 02, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-26475
CRITICAL
XWiki Platform <2.3-milestone-1 - RCE
Mar 02, 2023
CVSS 9.9
EPSS 0.35
CVE-2023-26474
CRITICAL
XWiki 13.10-13.10.10 - Improper Access Control via Text Area Property Execution
Mar 02, 2023
CVSS 9.9
EPSS 0.02
CVE-2023-26473
MEDIUM
XWiki Platform <1.3-rc-1 - Info Disclosure
Mar 02, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-26472
CRITICAL
XWiki 6.2.1-13.10.9 - Unauthenticated Remote Code Execution via Icon Theme Sheet Injection
Mar 02, 2023
CVSS 9.9
EPSS 0.10
CVE-2023-26471
CRITICAL
XWiki 11.6-13.10.9 - Authenticated Privilege Escalation via Async Macro
Mar 02, 2023
CVSS 9.9
EPSS 0.11
CVE-2023-26470
MEDIUM
XWiki < 14.0 - Uncontrolled Resource Consumption via Large Object Addition
Mar 02, 2023
CVSS 5.7
EPSS 0.01
CVE-2023-26056
MEDIUM
XWiki Platform <3.0-milestone-1 - Privilege Escalation
Mar 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-26480
HIGH
XWiki 12.10-13.10.9 - Stored Cross-Site Scripting via Live Data Macro
Mar 02, 2023
CVSS 8.9
EPSS 0.09
Products
xwiki-platform-oldcore 45
xwiki-platform-web-templates 23
xwiki-platform-web 15
xwiki-platform-administration-ui 11
xwiki-platform-rest-server 10
xwiki-platform-flamingo-skin-resources 6
xwiki-platform-appwithinminutes-ui 5
xwiki-platform-distribution-war 5
xwiki-platform-legacy-oldcore 5
xwiki-platform-attachment-ui 4
xwiki-platform-flamingo-theme-ui 4
xwiki-platform-livetable-ui 4
xwiki-platform-notifications-ui 4
xwiki-platform-scheduler-ui 4
xwiki-platform-search-ui 4
xwiki-platform-skin-skinx 4
xwiki-platform-wiki-ui-mainwiki 4
xwiki-platform-icon-ui 3
xwiki-platform-invitation-ui 3
xwiki-platform-panels-ui 3
xwiki-platform-search-solr-api 3
xwiki-platform-security-requiredrights-default 3
xwiki-platform 2
xwiki-platform-administration 2
xwiki-platform-filter-ui 2
xwiki-platform-help-ui 2
xwiki-platform-livedata-macro 2
xwiki-platform-localization-source-wiki 2
xwiki-platform-menu-ui 2
xwiki-platform-notifications-notifiers-default 2
Quick Filters