xwiki
285 tracked vulnerabilities.
CVE-2024-41947
CRITICAL
XWiki 11.8-15.10.7 - Stored Cross-Site Scripting via Edit Conflict
Jul 31, 2024
CVSS 9.0
EPSS 0.13
CVE-2024-37901
CRITICAL
XWiki 9.2-14.10.20 - Authenticated Remote Code Execution via SearchSuggestClass Instances
Jul 31, 2024
CVSS 9.9
EPSS 0.10
CVE-2024-37900
MEDIUM
XWiki 4.2-14.10.21 - Stored Cross-Site Scripting via Malicious Attachment Filename
Jul 31, 2024
CVSS 6.4
EPSS 0.05
CVE-2024-37898
MEDIUM
XWiki Platform 13.10.4-14.0 and 13.10.4-14.10.21 - Missing Authorization in Page Deletion
Jul 31, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-38369
CRITICAL
XWiki Platform - Privilege Escalation
Jun 24, 2024
CVSS 9.9
EPSS 0.01
CVE-2024-37899
CRITICAL
XWiki Platform 13.10.3-14.10.20 - Authenticated Remote Code Execution via User Profile Disabling
Jun 20, 2024
CVSS 9.0
EPSS 0.14
CVE-2024-31997
CRITICAL
XWiki Platform <4.10.19, 15.5.4, 15.10-rc-1 - RCE
Apr 10, 2024
CVSS 9.9
EPSS 0.54
CVE-2024-31996
CRITICAL
XWiki Platform <4.10.19, <15.5.4, <15.10-rc-1 - RCE
Apr 10, 2024
CVSS 10.0
EPSS 0.08
CVE-2024-31988
CRITICAL
XWiki Platform <4.10.19, 15.5.4, 15.10-rc-1 - RCE
Apr 10, 2024
CVSS 9.6
EPSS 0.07
CVE-2024-31987
CRITICAL
XWiki Platform <6.4-4.10.19, 15.5.4, 15.10-rc-1 - RCE
Apr 10, 2024
CVSS 9.9
EPSS 0.24
CVE-2024-31986
CRITICAL
XWiki Platform <4.10.19-15.10-rc-1 - RCE
Apr 10, 2024
CVSS 9.0
EPSS 0.08
CVE-2024-31985
MEDIUM
XWiki Platform <4.10.20-15.10-rc-1 - Info Disclosure
Apr 10, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-31984
CRITICAL
XWiki Platform <4.10.20, 15.5.4, 15.10-rc-1 - RCE
Apr 10, 2024
CVSS 9.9
EPSS 0.60
CVE-2024-31983
CRITICAL
XWiki Platform <4.10.20, 15.5.4, 15.10-rc-1 - RCE
Apr 10, 2024
CVSS 9.9
EPSS 0.23
CVE-2024-31982
CRITICAL
NUCLEI
XWiki Platform <4.10.20,15.5.4,15.10-rc-1 - RCE
Apr 10, 2024
CVSS 10.0
EPSS 0.94
CVE-2024-31981
CRITICAL
XWiki Platform <4.10.20, 15.5.4, 15.10-rc-1 - RCE
Apr 10, 2024
CVSS 9.9
EPSS 0.24
CVE-2024-31465
CRITICAL
XWiki 5.0-rc-1-14.10.19 - Authenticated Remote Code Execution via XWiki.SearchSuggestSourceClass Object Injection
Apr 10, 2024
CVSS 9.9
EPSS 0.35
CVE-2024-31464
MEDIUM
XWiki Platform 5.0-rc-1-14.10.18 - Authenticated Exposure of Sensitive Information via History Diff Feature
Apr 10, 2024
CVSS 6.8
EPSS 0.00
CVE-2024-26138
MEDIUM
XWiki Licensor Application < 1.24.2 - Unauthenticated Information Disclosure via LicenseJSON Document
Feb 21, 2024
CVSS 5.3
EPSS 0.00
CVE-2024-21651
HIGH
XWiki 14.10-14.10.17 - Denial of Service via Malformed TAR File Attachment
Jan 09, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-21648
HIGH
XWiki < 14.10.17, 15.0-rc-1-15.5.3 - Privilege Escalation via Rollback Action
Jan 09, 2024
CVSS 8.0
EPSS 0.00
CVE-2024-21650
CRITICAL
NUCLEI
XWiki < 4.10.20 - Remote code execution
Jan 08, 2024
CVSS 10.0
EPSS 0.93
CVE-2023-50732
HIGH
XWiki 8.3-14.10.6 - Unauthenticated Velocity Script Execution via Document Tree
Dec 21, 2023
CVSS 8.3
EPSS 0.01
CVE-2023-50723
CRITICAL
XWiki Platform 2.3-14.10.5 - Authenticated Remote Code Execution via Administration Interface
Dec 15, 2023
CVSS 9.9
EPSS 0.05
CVE-2023-50722
CRITICAL
XWiki Platform 2.3-14.10.4 - Unauthenticated Remote Code Execution via Configurable Admin Section URL Parameter
Dec 15, 2023
CVSS 9.6
EPSS 0.03
Products
xwiki 248
cryptpad 5
pro_macros 5
commons 4
xwiki-platform 4
xwiki-rendering 4
pdf_viewer_macro 3
change_request 2
ckeditor_integration 2
full_calendar_macro 2
admin_tools 1
application-collabora 1
application_licensing 1
blog_application 1
confluence_migrator 1
oauth_identity 1
openid_connect 1
org.xwiki.platform:xwiki-platform-legacy-oldcore 1
org.xwiki.platform:xwiki-platform-oldcore 1
rendering 1
wiki-platform 1
xwiki-commons 1
xwiki_enterprise 1
xwiki_watch 1
Quick Filters