xwiki

285 tracked vulnerabilities.

CVE-2023-35151 HIGH
XWiki 7.3-milestone-1-14.4.8 - Unauthenticated Exposure of Obfuscated Passwords via REST Endpoint
Jun 23, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-35150 CRITICAL
XWiki Platform 2.40m-2-14.4.8, 14.10.4, 15.0 - Remote Code Execution via Crafted URL Payload
Jun 23, 2023
CVSS 9.9
EPSS 0.35
CVE-2023-34467 HIGH
XWiki Platform <14.4.8-15.0-rc-1 - Info Disclosure
Jun 23, 2023
CVSS 7.5
EPSS 0.02
CVE-2023-34466 MEDIUM
XWiki 5.0.1-14.4.7 - Unauthorized Information Disclosure via Tags API
Jun 23, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-34465 CRITICAL
XWiki 11.8-rc-1-14.4.7 - Authenticated Privilege Escalation via Mail.MailConfig Page
Jun 23, 2023
CVSS 9.9
EPSS 0.01
CVE-2023-34464 CRITICAL
XWiki Platform 2.2.1-14.4.7 - Stored Cross-Site Scripting via DisplayContent or RenderContent Template
Jun 23, 2023
CVSS 9.0
EPSS 0.01
CVE-2023-35166 CRITICAL
XWiki 8.1-14.10.5 - Incorrect Authorization via Tip UI Extension
Jun 20, 2023
CVSS 9.9
EPSS 0.24
CVE-2023-32068 MEDIUM NUCLEI
XWiki Platform < 14.10.4 - Open Redirect via URL Parameter Manipulation
May 15, 2023
CVSS 4.7
EPSS 0.42
CVE-2023-32070 CRITICAL
XWiki Platform < 14.6-rc-1 - Cross-Site Scripting via HTML Attribute Injection
May 10, 2023
CVSS 9.0
EPSS 0.22
CVE-2023-32071 CRITICAL
XWiki Platform <2.2-14.4.8, <14.10.4, <15.0-rc-1 - XSS
May 09, 2023
CVSS 9.0
EPSS 0.34
CVE-2023-32069 CRITICAL
XWiki 3.3-milestone-2-14.10.3 - Incorrect Authorization
May 09, 2023
CVSS 9.9
EPSS 0.21
CVE-2023-31126 CRITICAL
org.xwiki.commons:xwiki-commons-xml - XSS
May 09, 2023
CVSS 9.0
EPSS 0.22
CVE-2023-29528 CRITICAL
XWiki Commons 4.2-milestone-1-14.9 - Cross-Site Scripting via Invalid HTML Comments
Apr 20, 2023
CVSS 9.0
EPSS 0.03
CVE-2023-29527 CRITICAL
XWiki 7.4.4-14.10.2 - Unauthenticated Remote Code Execution via Groovy Script Injection
Apr 19, 2023
CVSS 9.9
EPSS 0.10
CVE-2023-29526 CRITICAL
XWiki Platform 10.11.1-13.10.11 - Remote Code Execution via Async and Display Macros
Apr 19, 2023
CVSS 9.9
EPSS 0.23
CVE-2023-29525 CRITICAL
XWiki < 14.4.8, 12.6.1-13.10.11, 14.6-rc-1-14.10.3 - Code Injection via LegacyNotificationAdministration since Parameter
Apr 19, 2023
CVSS 9.9
EPSS 0.54
CVE-2023-29524 CRITICAL
XWiki < 14.10.3 - Authenticated Remote Code Execution via Scheduler Job Script Injection
Apr 19, 2023
CVSS 9.9
EPSS 0.48
CVE-2023-29523 CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via Script Macro Injection
Apr 19, 2023
CVSS 9.9
EPSS 0.11
CVE-2023-29522 CRITICAL
XWiki < 14.4.8 - Remote Code Execution via Crafted Page Name
Apr 19, 2023
CVSS 9.9
EPSS 0.36
CVE-2023-29521 HIGH
XWiki < 13.10.11 - Authenticated Remote Code Execution via Macro.VFSTreeMacro
Apr 19, 2023
CVSS 8.4
EPSS 0.15
CVE-2023-29520 MEDIUM
XWiki < 13.10.11 - Denial of Service via Corrupted Translation Document
Apr 19, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-29519 CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via Attachment Selector Property Field
Apr 19, 2023
CVSS 9.0
EPSS 0.05
CVE-2023-29518 CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via Invitation.InvitationCommon Page
Apr 19, 2023
CVSS 9.9
EPSS 0.29
CVE-2023-29517 HIGH
XWiki < 13.10.11 - Unauthenticated Exposure of Sensitive Information via Office Document Viewer Macro
Apr 19, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-29516 CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via AttachmentSelector Cancel Button
Apr 19, 2023
CVSS 9.9
EPSS 0.27