xwiki

285 tracked vulnerabilities.

CVE-2026-33137 CRITICAL
XWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName}
May 20, 2026
EPSS 0.00
CVE-2026-23734 CRITICAL
XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slash
May 20, 2026
EPSS 0.00
CVE-2026-40105 MEDIUM NUCLEI
XWiki has Reflected Cross-Site Scripting (XSS) in its page history compare functionality
Apr 15, 2026
CVSS 6.1
EPSS 0.01
CVE-2026-40104 HIGH
XWiki's REST APIs can list all pages/spaces, leading to unavailability
Apr 15, 2026
CVSS 8.2
EPSS 0.00
CVE-2026-33229 CRITICAL
XWiki Platform affected by remote code execution with script right through unprotected Velocity scripting API
Apr 08, 2026
CVSS 9.8
EPSS 0.00
CVE-2026-26000 MEDIUM
XWiki Platform <17.9.0, <17.4.6, <16.10.13 - XSS
Feb 12, 2026
CVSS 6.1
EPSS 0.00
CVE-2026-24128 MEDIUM NUCLEI
XWiki Platform 7.0-milestone-2-16.10.11, 17.0.0-rc-1-17.4.4, 17.5.0-rc-1-17.7.0 - Reflected Cross-Site Scripting
Jan 24, 2026
CVSS 6.1
EPSS 0.00
CVE-2025-51846 HIGH
CryptPad unbounded WebSocket frame flood
Apr 30, 2026
CVSS 7.5
EPSS 0.01
CVE-2025-66024 CRITICAL
XWiki Blog Application < 9.15.7 - Stored Cross-Site Scripting via Blog Post Title
Mar 04, 2026
CVSS 9.0
EPSS 0.01
CVE-2025-65091 CRITICAL
XWiki Full Calendar Macro < 2.4.5 - SQL Injection
Jan 10, 2026
CVSS 10.0
EPSS 0.00
CVE-2025-65090 MEDIUM
XWiki Full Calendar Macro < 2.4.6 - Unauthenticated Exposure of Sensitive Information via Calendar.JSONService
Jan 10, 2026
CVSS 5.3
EPSS 0.00
CVE-2025-66474 HIGH
XWiki Rendering < 16.10.10, 17.0.0-rc-1-17.4.2, 17.5.0-rc-1-17.5.0 - Remote Code Execution via HTML Macro Injection
Dec 10, 2025
CVSS 8.8
EPSS 0.01
CVE-2025-66473 HIGH
XWiki < 16.10.11 - Denial of Service via Unrestricted REST API Item Requests
Dec 10, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-66472 MEDIUM NUCLEI
XWiki Platform <16.10.9, <17.0.0-rc-1 to <17.4.1 - XSS
Dec 10, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-65036 HIGH
XWiki Remote Macros < 1.27.1 - Remote Code Execution via Unauthorized Velocity Execution
Dec 05, 2025
CVSS 8.3
EPSS 0.01
CVE-2025-55749 HIGH NUCLEI
XWiki <16.10.11, 17.4.4, 17.7.0 - Info Disclosure
Dec 01, 2025
CVSS 7.5
EPSS 0.01
CVE-2025-65089 MEDIUM
XWiki Remote Macros < 1.27.0 - Missing Authorization in View File Macro
Nov 19, 2025
CVSS 6.8
EPSS 0.00
CVE-2025-52472 CRITICAL NUCLEI
XWiki Platform 4.3-milestone-1-16.10.8, 17.0.0-rc-1-17.4.1 - SQL Injection via REST Search orderField Parameter
Oct 06, 2025
EPSS 0.00
CVE-2025-55728 CRITICAL
XWiki Remote Macros 1.0-1.26.4 - Remote Code Execution via Panel Macro Classes Parameter
Sep 09, 2025
CVSS 10.0
EPSS 0.04
CVE-2025-55727 CRITICAL
XWiki Remote Macros 1.0-1.26.4 - Remote Code Execution via Column Macro Width Parameter
Sep 09, 2025
CVSS 10.0
EPSS 0.08
CVE-2025-55748 HIGH NUCLEI
XWiki Platform <16.10.6 - Info Disclosure
Sep 03, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-55747 CRITICAL NUCLEI
XWiki Platform <16.10.6 - Info Disclosure
Sep 03, 2025
CVSS 9.1
EPSS 0.01
CVE-2025-58049 MEDIUM
XWiki Platform <16.4.8-17.4.0-rc-1 - Info Disclosure
Aug 28, 2025
CVSS 5.8
EPSS 0.00
CVE-2025-51991 HIGH NUCLEI
XWiki < 17.3.0 - Authenticated Server-Side Template Injection in HTTP Meta Info Field
Aug 20, 2025
CVSS 8.8
EPSS 0.04
CVE-2025-51990 MEDIUM NUCLEI
XWiki < 17.3.0 - Authenticated Stored Cross-Site Scripting in Administration Presentation Fields
Aug 20, 2025
CVSS 4.8
EPSS 0.00