xwiki

285 tracked vulnerabilities.

CVE-2025-54125 MEDIUM NUCLEI
XWiki Platform <17.1.0 - Info Disclosure
Aug 06, 2025
CVSS 6.5
EPSS 0.01
CVE-2025-54124 MEDIUM
XWiki Platform <17.1.0 - Info Disclosure
Aug 06, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-32430 MEDIUM NUCLEI
XWiki Platform - Cross-Site Scripting
Aug 06, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-54385 CRITICAL
XWiki < 16.10.6 - SQL Injection via Hibernate Query Sanitization Bypass
Jul 26, 2025
CVSS 9.8
EPSS 0.01
CVE-2025-32429 CRITICAL NUCLEI
XWiki Platform - SQL Injection
Jul 24, 2025
CVSS 9.8
EPSS 0.33
CVE-2025-53836 CRITICAL
XWiki Rendering <13.10.11-14.4.7-14.10 - RCE
Jul 15, 2025
CVSS 9.9
EPSS 0.05
CVE-2025-53835 CRITICAL
XWiki 5.4.5-14.10 - Stored Cross-Site Scripting via Raw Block HTML Injection
Jul 14, 2025
CVSS 9.0
EPSS 0.04
CVE-2025-49591 CRITICAL
CryptPad < 2025.3.0 - Two-Factor Authentication Bypass via URL-Encoded Path Parameter
Jun 18, 2025
CVSS 9.1
EPSS 0.00
CVE-2025-49590 MEDIUM
CryptPad < 2025.3.0 - Cross-Site Scripting via Link Bouncer Bypass
Jun 18, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-49587 HIGH
XWiki 15.9-15.10.15 - Stored Cross-Site Scripting via Notification Displayer Object
Jun 13, 2025
CVSS 8.0
EPSS 0.01
CVE-2025-49586 HIGH
XWiki 7.3-16.4.6 - Authenticated Remote Code Execution via App Within Minutes Application Edit
Jun 13, 2025
CVSS 8.8
EPSS 0.09
CVE-2025-49585 HIGH
XWiki - Code Injection via XClass Definition
Jun 13, 2025
CVSS 8.0
EPSS 0.01
CVE-2025-49584 HIGH
XWiki <16.4.6, 16.5.0-rc-1, 16.10.2, 17.0.0-rc-1 - Info Disclosure
Jun 13, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-49583 LOW
XWiki < 15.10.16 - Insufficient UI Warning of Dangerous Operations in Notification Email Renderer
Jun 13, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-49582 HIGH
XWiki 15.9-16.4.6 - Insufficient UI Warning of Dangerous Operations in Macro Parameter Analysis
Jun 13, 2025
CVSS 8.0
EPSS 0.01
CVE-2025-49581 HIGH
XWiki Wiki Macro Parameters - Programming Rights Code Execution
Jun 13, 2025
CVSS 8.8
EPSS 0.04
CVE-2025-49580 HIGH
XWiki 7.4.5-16.4.6, 16.10.0-16.10.3, 17.0.0-rc-1-17.0.0 - Incorrect Privilege Assignment via Page Link Renaming
Jun 13, 2025
CVSS 8.0
EPSS 0.01
CVE-2025-48063 HIGH
XWiki 16.10.0-16.10.3 - Authenticated Remote Code Execution via Required Rights Bypass
May 21, 2025
CVSS 8.8
EPSS 0.05
CVE-2025-46558 CRITICAL
XWiki 8.2-8.9 - Stored Cross-Site Scripting via Markdown HTML Import
Apr 30, 2025
CVSS 9.0
EPSS 0.03
CVE-2025-46557 CRITICAL
XWiki <15.10.14, <16.4.6, <16.10.0-rc-1 - Privilege Escalation
Apr 30, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-46554 MEDIUM NUCLEI
XWiki <14.10.22, <15.10.12, <16.4.3, <16.7.0 - Info Disclosure
Apr 30, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-32974 CRITICAL
XWiki 15.9-15.10.7 and 16.0.0-16.1.0 - Privilege Escalation via TextArea Default Content Type
Apr 30, 2025
CVSS 9.0
EPSS 0.01
CVE-2025-32973 CRITICAL
XWiki 15.9-15.10.12, 16.0.0-16.4.3, 16.5.0-16.8.0-rc-1 - Missing Authorization for Programming Rights
Apr 30, 2025
CVSS 9.0
EPSS 0.02
CVE-2025-32972 LOW
XWiki 6.1-15.10.11, 16.0.0-16.4.2, 16.5.0-16.7.0 - Authenticated Cache Clearing via LESS Compiler
Apr 30, 2025
CVSS 2.7
EPSS 0.00
CVE-2025-32971 LOW
XWiki 4.5.1-15.10.12, 16.0.0-rc-1-16.4.3, 16.5.0-rc-1-16.8.0-rc-1 - Incorrect Authorization in Solr Script Service
Apr 30, 2025
CVSS 3.8
EPSS 0.00