xwiki

285 tracked vulnerabilities.

CVE-2023-27480 HIGH
XWiki Platform < 13.10.11 - XML External Entity Injection via XAR Import
Mar 07, 2023
CVSS 7.7
EPSS 0.00
CVE-2023-27479 CRITICAL
XWiki 6.3-13.10.10 - Authenticated Remote Code Execution via UIX Parameter Injection
Mar 07, 2023
CVSS 9.9
EPSS 0.15
CVE-2023-26476 HIGH
XWiki Platform <14.7-rc-1, <13.4.4, <13.10.9 - Info Disclosure
Mar 02, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-26475 CRITICAL
XWiki Platform <2.3-milestone-1 - RCE
Mar 02, 2023
CVSS 9.9
EPSS 0.35
CVE-2023-26474 CRITICAL
XWiki 13.10-13.10.10 - Improper Access Control via Text Area Property Execution
Mar 02, 2023
CVSS 9.9
EPSS 0.02
CVE-2023-26473 MEDIUM
XWiki Platform <1.3-rc-1 - Info Disclosure
Mar 02, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-26472 CRITICAL
XWiki 6.2.1-13.10.9 - Unauthenticated Remote Code Execution via Icon Theme Sheet Injection
Mar 02, 2023
CVSS 9.9
EPSS 0.10
CVE-2023-26471 CRITICAL
XWiki 11.6-13.10.9 - Authenticated Privilege Escalation via Async Macro
Mar 02, 2023
CVSS 9.9
EPSS 0.11
CVE-2023-26470 MEDIUM
XWiki < 14.0 - Uncontrolled Resource Consumption via Large Object Addition
Mar 02, 2023
CVSS 5.7
EPSS 0.01
CVE-2023-26056 MEDIUM
XWiki Platform <3.0-milestone-1 - Privilege Escalation
Mar 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-26055 CRITICAL
XWiki Commons <3.1-milestone-1 - Code Injection
Mar 02, 2023
CVSS 9.9
EPSS 0.05
CVE-2023-26480 HIGH
XWiki 12.10-13.10.9 - Stored Cross-Site Scripting via Live Data Macro
Mar 02, 2023
CVSS 8.9
EPSS 0.09
CVE-2023-26479 MEDIUM
XWiki Platform <6.0 - Info Disclosure
Mar 02, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-26478 MEDIUM
XWiki Platform <14.3-rc-1 - Info Disclosure
Mar 02, 2023
CVSS 6.6
EPSS 0.05
CVE-2023-26477 CRITICAL
XWiki Platform <13.10.10, <14.9-rc-1, <14.4.6 - Code Injection
Mar 02, 2023
CVSS 10.0
EPSS 0.40
CVE-2023-22457 CRITICAL
CKEditor Integration UI <1.64.3 - CSRF
Jan 04, 2023
CVSS 9.0
EPSS 0.01
CVE-2022-41933 MEDIUM
XWiki 13.1-13.10.8 - Plaintext Password Storage in Forgot Password Feature
Nov 23, 2022
CVSS 6.2
EPSS 0.00
CVE-2022-41932 HIGH
XWiki < 13.10.8 - Denial of Service via Crafted User Identifier in Login Form
Nov 23, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-41935 MEDIUM
XWiki 12.10.11-13.10.8 - Unauthenticated Exposure of Sensitive Information via Livetable Queries
Nov 23, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-41934 CRITICAL
XWiki Platform < 13.10.8 - Authenticated Remote Code Execution via Menu Macro Injection
Nov 23, 2022
CVSS 9.9
EPSS 0.24
CVE-2022-41931 CRITICAL
xwiki-platform-icon-ui - Eval Injection
Nov 23, 2022
CVSS 9.9
EPSS 0.19
CVE-2022-41930 HIGH
XWiki 12.4-13.10.6 - Unauthenticated Missing Authorization in User Profile UI
Nov 23, 2022
CVSS 7.5
EPSS 0.01
CVE-2022-41929 MEDIUM
XWiki 11.7-13.10.6, 14.0.0-14.4.1 - Missing Authorization in User#setDisabledStatus
Nov 23, 2022
CVSS 4.9
EPSS 0.00
CVE-2022-41928 CRITICAL
XWiki 5.0-13.10.6 - Eval Injection in AttachmentSelector.xml
Nov 23, 2022
CVSS 9.9
EPSS 0.06
CVE-2022-41927 HIGH
XWiki Platform 3.2-13.10.6 - Cross-Site Request Forgery in Tag Management
Nov 23, 2022
CVSS 7.4
EPSS 0.01