xwiki
285 tracked vulnerabilities.
CVE-2023-27480
HIGH
XWiki Platform < 13.10.11 - XML External Entity Injection via XAR Import
Mar 07, 2023
CVSS 7.7
EPSS 0.00
CVE-2023-27479
CRITICAL
XWiki 6.3-13.10.10 - Authenticated Remote Code Execution via UIX Parameter Injection
Mar 07, 2023
CVSS 9.9
EPSS 0.15
CVE-2023-26476
HIGH
XWiki Platform <14.7-rc-1, <13.4.4, <13.10.9 - Info Disclosure
Mar 02, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-26475
CRITICAL
XWiki Platform <2.3-milestone-1 - RCE
Mar 02, 2023
CVSS 9.9
EPSS 0.35
CVE-2023-26474
CRITICAL
XWiki 13.10-13.10.10 - Improper Access Control via Text Area Property Execution
Mar 02, 2023
CVSS 9.9
EPSS 0.02
CVE-2023-26473
MEDIUM
XWiki Platform <1.3-rc-1 - Info Disclosure
Mar 02, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-26472
CRITICAL
XWiki 6.2.1-13.10.9 - Unauthenticated Remote Code Execution via Icon Theme Sheet Injection
Mar 02, 2023
CVSS 9.9
EPSS 0.10
CVE-2023-26471
CRITICAL
XWiki 11.6-13.10.9 - Authenticated Privilege Escalation via Async Macro
Mar 02, 2023
CVSS 9.9
EPSS 0.11
CVE-2023-26470
MEDIUM
XWiki < 14.0 - Uncontrolled Resource Consumption via Large Object Addition
Mar 02, 2023
CVSS 5.7
EPSS 0.01
CVE-2023-26056
MEDIUM
XWiki Platform <3.0-milestone-1 - Privilege Escalation
Mar 02, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-26055
CRITICAL
XWiki Commons <3.1-milestone-1 - Code Injection
Mar 02, 2023
CVSS 9.9
EPSS 0.05
CVE-2023-26480
HIGH
XWiki 12.10-13.10.9 - Stored Cross-Site Scripting via Live Data Macro
Mar 02, 2023
CVSS 8.9
EPSS 0.09
CVE-2023-26479
MEDIUM
XWiki Platform <6.0 - Info Disclosure
Mar 02, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-26478
MEDIUM
XWiki Platform <14.3-rc-1 - Info Disclosure
Mar 02, 2023
CVSS 6.6
EPSS 0.05
CVE-2023-26477
CRITICAL
XWiki Platform <13.10.10, <14.9-rc-1, <14.4.6 - Code Injection
Mar 02, 2023
CVSS 10.0
EPSS 0.40
CVE-2023-22457
CRITICAL
CKEditor Integration UI <1.64.3 - CSRF
Jan 04, 2023
CVSS 9.0
EPSS 0.01
CVE-2022-41933
MEDIUM
XWiki 13.1-13.10.8 - Plaintext Password Storage in Forgot Password Feature
Nov 23, 2022
CVSS 6.2
EPSS 0.00
CVE-2022-41932
HIGH
XWiki < 13.10.8 - Denial of Service via Crafted User Identifier in Login Form
Nov 23, 2022
CVSS 7.5
EPSS 0.00
CVE-2022-41935
MEDIUM
XWiki 12.10.11-13.10.8 - Unauthenticated Exposure of Sensitive Information via Livetable Queries
Nov 23, 2022
CVSS 5.3
EPSS 0.00
CVE-2022-41934
CRITICAL
XWiki Platform < 13.10.8 - Authenticated Remote Code Execution via Menu Macro Injection
Nov 23, 2022
CVSS 9.9
EPSS 0.24
CVE-2022-41931
CRITICAL
xwiki-platform-icon-ui - Eval Injection
Nov 23, 2022
CVSS 9.9
EPSS 0.19
CVE-2022-41930
HIGH
XWiki 12.4-13.10.6 - Unauthenticated Missing Authorization in User Profile UI
Nov 23, 2022
CVSS 7.5
EPSS 0.01
CVE-2022-41929
MEDIUM
XWiki 11.7-13.10.6, 14.0.0-14.4.1 - Missing Authorization in User#setDisabledStatus
Nov 23, 2022
CVSS 4.9
EPSS 0.00
CVE-2022-41928
CRITICAL
XWiki 5.0-13.10.6 - Eval Injection in AttachmentSelector.xml
Nov 23, 2022
CVSS 9.9
EPSS 0.06
CVE-2022-41927
HIGH
XWiki Platform 3.2-13.10.6 - Cross-Site Request Forgery in Tag Management
Nov 23, 2022
CVSS 7.4
EPSS 0.01
Products
xwiki 248
cryptpad 5
pro_macros 5
commons 4
xwiki-platform 4
xwiki-rendering 4
pdf_viewer_macro 3
change_request 2
ckeditor_integration 2
full_calendar_macro 2
admin_tools 1
application-collabora 1
application_licensing 1
blog_application 1
confluence_migrator 1
oauth_identity 1
openid_connect 1
org.xwiki.platform:xwiki-platform-legacy-oldcore 1
org.xwiki.platform:xwiki-platform-oldcore 1
rendering 1
wiki-platform 1
xwiki-commons 1
xwiki_enterprise 1
xwiki_watch 1
Quick Filters