xwiki
285 tracked vulnerabilities.
CVE-2025-54125
MEDIUM
NUCLEI
XWiki Platform <17.1.0 - Info Disclosure
Aug 06, 2025
CVSS 6.5
EPSS 0.01
CVE-2025-54124
MEDIUM
XWiki Platform <17.1.0 - Info Disclosure
Aug 06, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-32430
MEDIUM
NUCLEI
XWiki Platform - Cross-Site Scripting
Aug 06, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-54385
CRITICAL
XWiki < 16.10.6 - SQL Injection via Hibernate Query Sanitization Bypass
Jul 26, 2025
CVSS 9.8
EPSS 0.01
CVE-2025-32429
CRITICAL
NUCLEI
XWiki Platform - SQL Injection
Jul 24, 2025
CVSS 9.8
EPSS 0.33
CVE-2025-53836
CRITICAL
XWiki Rendering <13.10.11-14.4.7-14.10 - RCE
Jul 15, 2025
CVSS 9.9
EPSS 0.05
CVE-2025-53835
CRITICAL
XWiki 5.4.5-14.10 - Stored Cross-Site Scripting via Raw Block HTML Injection
Jul 14, 2025
CVSS 9.0
EPSS 0.04
CVE-2025-49591
CRITICAL
CryptPad < 2025.3.0 - Two-Factor Authentication Bypass via URL-Encoded Path Parameter
Jun 18, 2025
CVSS 9.1
EPSS 0.00
CVE-2025-49590
MEDIUM
CryptPad < 2025.3.0 - Cross-Site Scripting via Link Bouncer Bypass
Jun 18, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-49587
HIGH
XWiki 15.9-15.10.15 - Stored Cross-Site Scripting via Notification Displayer Object
Jun 13, 2025
CVSS 8.0
EPSS 0.01
CVE-2025-49586
HIGH
XWiki 7.3-16.4.6 - Authenticated Remote Code Execution via App Within Minutes Application Edit
Jun 13, 2025
CVSS 8.8
EPSS 0.09
CVE-2025-49585
HIGH
XWiki - Code Injection via XClass Definition
Jun 13, 2025
CVSS 8.0
EPSS 0.01
CVE-2025-49584
HIGH
XWiki <16.4.6, 16.5.0-rc-1, 16.10.2, 17.0.0-rc-1 - Info Disclosure
Jun 13, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-49583
LOW
XWiki < 15.10.16 - Insufficient UI Warning of Dangerous Operations in Notification Email Renderer
Jun 13, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-49582
HIGH
XWiki 15.9-16.4.6 - Insufficient UI Warning of Dangerous Operations in Macro Parameter Analysis
Jun 13, 2025
CVSS 8.0
EPSS 0.01
CVE-2025-49581
HIGH
XWiki Wiki Macro Parameters - Programming Rights Code Execution
Jun 13, 2025
CVSS 8.8
EPSS 0.04
CVE-2025-49580
HIGH
XWiki 7.4.5-16.4.6, 16.10.0-16.10.3, 17.0.0-rc-1-17.0.0 - Incorrect Privilege Assignment via Page Link Renaming
Jun 13, 2025
CVSS 8.0
EPSS 0.01
CVE-2025-48063
HIGH
XWiki 16.10.0-16.10.3 - Authenticated Remote Code Execution via Required Rights Bypass
May 21, 2025
CVSS 8.8
EPSS 0.05
CVE-2025-46558
CRITICAL
XWiki 8.2-8.9 - Stored Cross-Site Scripting via Markdown HTML Import
Apr 30, 2025
CVSS 9.0
EPSS 0.03
CVE-2025-46557
CRITICAL
XWiki <15.10.14, <16.4.6, <16.10.0-rc-1 - Privilege Escalation
Apr 30, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-46554
MEDIUM
NUCLEI
XWiki <14.10.22, <15.10.12, <16.4.3, <16.7.0 - Info Disclosure
Apr 30, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-32974
CRITICAL
XWiki 15.9-15.10.7 and 16.0.0-16.1.0 - Privilege Escalation via TextArea Default Content Type
Apr 30, 2025
CVSS 9.0
EPSS 0.01
CVE-2025-32973
CRITICAL
XWiki 15.9-15.10.12, 16.0.0-16.4.3, 16.5.0-16.8.0-rc-1 - Missing Authorization for Programming Rights
Apr 30, 2025
CVSS 9.0
EPSS 0.02
CVE-2025-32972
LOW
XWiki 6.1-15.10.11, 16.0.0-16.4.2, 16.5.0-16.7.0 - Authenticated Cache Clearing via LESS Compiler
Apr 30, 2025
CVSS 2.7
EPSS 0.00
CVE-2025-32971
LOW
XWiki 4.5.1-15.10.12, 16.0.0-rc-1-16.4.3, 16.5.0-rc-1-16.8.0-rc-1 - Incorrect Authorization in Solr Script Service
Apr 30, 2025
CVSS 3.8
EPSS 0.00
Products
xwiki 248
cryptpad 5
pro_macros 5
commons 4
xwiki-platform 4
xwiki-rendering 4
pdf_viewer_macro 3
change_request 2
ckeditor_integration 2
full_calendar_macro 2
admin_tools 1
application-collabora 1
application_licensing 1
blog_application 1
confluence_migrator 1
oauth_identity 1
openid_connect 1
org.xwiki.platform:xwiki-platform-legacy-oldcore 1
org.xwiki.platform:xwiki-platform-oldcore 1
rendering 1
wiki-platform 1
xwiki-commons 1
xwiki_enterprise 1
xwiki_watch 1
Quick Filters