xwiki

285 tracked vulnerabilities.

CVE-2023-29515 HIGH
XWiki < 13.10.11 - Authenticated JavaScript Injection via App Within Minutes Space Admin Right
Apr 19, 2023
CVSS 7.7
EPSS 0.07
CVE-2023-29514 CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via Document Edit
Apr 19, 2023
CVSS 9.9
EPSS 0.30
CVE-2023-29513 MEDIUM
XWiki < 14.10.1 - Unauthenticated User Creation via Distribution First Admin User Endpoint
Apr 19, 2023
CVSS 5.0
EPSS 0.02
CVE-2023-29512 CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via Improper Escaping in Attachment Handling
Apr 19, 2023
CVSS 9.9
EPSS 0.29
CVE-2023-29510 CRITICAL
XWiki < 14.10.2 - Authenticated Remote Code Execution via User Translation Override
Apr 19, 2023
CVSS 9.9
EPSS 0.30
CVE-2023-29213 CRITICAL
XWiki Platform < 13.10.11 - Authenticated Remote Code Execution via URL Expression Injection
Apr 17, 2023
CVSS 9.0
EPSS 0.04
CVE-2023-30537 CRITICAL
XWiki 12.6.6-13.10.10 - Authenticated Remote Code Execution via FlamingoThemesCode.WebHome Style Property
Apr 16, 2023
CVSS 9.9
EPSS 0.29
CVE-2023-29511 CRITICAL
XWiki 1.7-13.10.10 - Authenticated Remote Code Execution via Section ID Injection in AdminFieldsDisplaySheet
Apr 16, 2023
CVSS 9.9
EPSS 0.29
CVE-2023-29509 CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via DocumentTree Macro Parameter Injection
Apr 16, 2023
CVSS 9.9
EPSS 0.36
CVE-2023-29508 HIGH
XWiki < 13.10.11 - Stored Cross-Site Scripting via Live Data Macro
Apr 16, 2023
CVSS 8.9
EPSS 0.04
CVE-2023-29507 CRITICAL
XWiki 14.4.1-14.4.6 and 14.5-14.9 - Privilege Escalation via Document Script API
Apr 16, 2023
CVSS 9.1
EPSS 0.10
CVE-2023-29506 MEDIUM NUCLEI
XWiki 13.10.8-13.10.10 - Authenticated Cross-Site Scripting via Endpoint URL Injection
Apr 16, 2023
CVSS 5.4
EPSS 0.12
CVE-2023-29214 CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via IncludedDocuments Panel
Apr 16, 2023
CVSS 9.9
EPSS 0.06
CVE-2023-29212 CRITICAL
XWiki 14.0-14.4.7 - Authenticated Remote Code Execution via Insufficient Escaping in Included Documents Edit Panel
Apr 16, 2023
CVSS 9.9
EPSS 0.08
CVE-2023-29211 CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via Improper WikiId Parameter Escaping
Apr 16, 2023
CVSS 9.9
EPSS 0.08
CVE-2023-29210 CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via Notification Preferences Macro
Apr 15, 2023
CVSS 9.9
EPSS 0.06
CVE-2023-29209 CRITICAL
XWiki <13.10.11 - Code Execution via Legacy Notification Activity Macro
Apr 15, 2023
CVSS 9.9
EPSS 0.19
CVE-2023-29208 HIGH
XWiki < 13.10.11 - Unauthorized Deleted Document Access
Apr 15, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-29207 HIGH
XWiki 1.9-13.10.9 - Stored Cross-Site Scripting via Livetable Macro Column Names
Apr 15, 2023
CVSS 8.9
EPSS 0.18
CVE-2023-29206 CRITICAL
XWiki 3.0-14.8 - Authenticated Stored Cross-Site Scripting via JavaScript or StyleSheet XObject
Apr 15, 2023
CVSS 9.0
EPSS 0.04
CVE-2023-29205 CRITICAL
XWiki < 14.7 and xwiki-platform-rendering-xwiki < 14.8-rc-1 - Stored Cross-Site Scripting via HTML Macro
Apr 15, 2023
CVSS 9.9
EPSS 0.02
CVE-2023-29204 MEDIUM NUCLEI
XWiki 6.0-13.10.9 - Open Redirect via URL Scheme Omission
Apr 15, 2023
CVSS 4.7
EPSS 0.01
CVE-2023-29203 LOW
XWiki 13.9-13.10.8 - Unauthorized Exposure of Private User Information via uorgsuggest.vm
Apr 15, 2023
CVSS 3.7
EPSS 0.00
CVE-2023-29202 CRITICAL
XWiki 1.8-14.5 - Stored Cross-Site Scripting via RSS Macro Content Parameter
Apr 15, 2023
CVSS 9.0
EPSS 0.11
CVE-2023-29201 CRITICAL
XWiki 5.0-14.4 and xwiki-commons-xml 4.2-milestone-1-14.5 - Stored Cross-Site Scripting via HTML Cleaner Restricted Mode
Apr 15, 2023
CVSS 9.0
EPSS 0.09