Xwiki

Xwiki

244 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 12.02.2026 20:30:07
  • Zuletzt bearbeitet 19.02.2026 19:22:44

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.9.0, 17.4.6, and 16.10.13, it's possible using comments to inject CSS that would transform the full wiki in a link area leading to a ...

  • EPSS 0.06%
  • Veröffentlicht 23.01.2026 23:18:31
  • Zuletzt bearbeitet 12.02.2026 16:47:29

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 7.0-milestone-2 through 16.10.11, 17.0.0-rc-1 through 17.4.4, and 17.5.0-rc-1 through 17.7.0 contain a reflected Cross-site Scripting (X...

  • EPSS 0.06%
  • Veröffentlicht 10.12.2025 21:51:55
  • Zuletzt bearbeitet 19.12.2025 17:14:44

XWiki is an open-source wiki software platform. Versions 16.10.10 and below, 17.0.0-rc-1 through 17.4.3 and 17.5.0-rc-1 through 17.6.0 contain a REST API which doesn't enforce any limits for the number of items that can be requested in a single reque...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 10.12.2025 21:34:47
  • Zuletzt bearbeitet 18.02.2026 15:57:46

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 6.2-milestone-1 through 16.10.9 and 17.0.0-rc-1 through 17.4.1 of both XWiki Platform Flamingo Skin Resources and XWiki Platform Web Te...

  • EPSS 1.55%
  • Veröffentlicht 01.12.2025 20:09:46
  • Zuletzt bearbeitet 02.03.2026 22:02:46

XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is using the XWiki Jetty package (XJetty), a context is exposed to statically access any file located in the webapp/ folder. It allows ac...

  • EPSS 0.36%
  • Veröffentlicht 03.09.2025 20:19:45
  • Zuletzt bearbeitet 10.09.2025 17:24:13

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-2 through 16.10.6, configuration files are accessible through jsx and sx endpoints. It's possible to access and read co...

  • EPSS 1.27%
  • Veröffentlicht 03.09.2025 20:12:12
  • Zuletzt bearbeitet 10.09.2025 17:47:28

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 6.1-milestone-2 through 16.10.6, configuration files are accessible through the webjars API. This is fixed in version 16.10.7.

Exploit
  • EPSS 0.05%
  • Veröffentlicht 28.08.2025 17:43:39
  • Zuletzt bearbeitet 02.09.2025 17:34:25

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions from 14.4.2 to before 16.4.8, 16.5.0-rc-1 to before 16.10.7, and 17.0.0-rc-1 to before 17.4.0-rc-1, the PDF export jobs store sensiti...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 20.08.2025 00:00:00
  • Zuletzt bearbeitet 11.09.2025 13:51:18

XWiki through version 17.3.0 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities in the Administration interface, specifically under the Presentation section of the Global Preferences panel. An authenticated administrator can in...

Exploit
  • EPSS 1.4%
  • Veröffentlicht 20.08.2025 00:00:00
  • Zuletzt bearbeitet 11.09.2025 13:50:55

XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, specifically within the HTTP Meta Info field of the Global Preferences Presentation section. An authenticated administrator can injec...