Xwiki

Xwiki

248 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 19.54%
  • Veröffentlicht 20.05.2026 18:39:32
  • Zuletzt bearbeitet 21.05.2026 16:04:53

XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to read configuration files by using URLs such as http://localhost:8080/bin/ssx/Main/WebHome?resource=/../../WEB-INF/xwiki.cfg&minify...

  • EPSS 0.55%
  • Veröffentlicht 15.04.2026 00:07:23
  • Zuletzt bearbeitet 23.04.2026 13:52:12

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 10.4-rc-1, through 16.10.15, 17.0.0-rc-1, through 17.4.7 and 17.5.0-rc-1 through 17.10.0 contain a reflected cross-site scripting vulne...

  • EPSS 0.41%
  • Veröffentlicht 15.04.2026 00:01:58
  • Zuletzt bearbeitet 23.04.2026 13:52:54

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 1.8-rc-1, 17.0.0-rc-1 and 17.5.0-rc-1 and prior include a resource exhaustion vulnerability in REST API endpoints such as /xwiki/rest/wi...

Exploit
  • EPSS 0.54%
  • Veröffentlicht 08.04.2026 14:53:35
  • Zuletzt bearbeitet 14.04.2026 20:08:07

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows any user with script right to bypass the sandboxing of the Velocity scr...

  • EPSS 0.28%
  • Veröffentlicht 12.02.2026 20:30:07
  • Zuletzt bearbeitet 19.02.2026 19:22:44

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.9.0, 17.4.6, and 16.10.13, it's possible using comments to inject CSS that would transform the full wiki in a link area leading to a ...

  • EPSS 0.5%
  • Veröffentlicht 23.01.2026 23:18:31
  • Zuletzt bearbeitet 12.02.2026 16:47:29

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 7.0-milestone-2 through 16.10.11, 17.0.0-rc-1 through 17.4.4, and 17.5.0-rc-1 through 17.7.0 contain a reflected Cross-site Scripting (X...

  • EPSS 0.34%
  • Veröffentlicht 10.12.2025 21:51:55
  • Zuletzt bearbeitet 19.12.2025 17:14:44

XWiki is an open-source wiki software platform. Versions 16.10.10 and below, 17.0.0-rc-1 through 17.4.3 and 17.5.0-rc-1 through 17.6.0 contain a REST API which doesn't enforce any limits for the number of items that can be requested in a single reque...

Exploit
  • EPSS 0.46%
  • Veröffentlicht 10.12.2025 21:34:47
  • Zuletzt bearbeitet 18.02.2026 15:57:46

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 6.2-milestone-1 through 16.10.9 and 17.0.0-rc-1 through 17.4.1 of both XWiki Platform Flamingo Skin Resources and XWiki Platform Web Te...

  • EPSS 1.38%
  • Veröffentlicht 01.12.2025 20:09:46
  • Zuletzt bearbeitet 02.03.2026 22:02:46

XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is using the XWiki Jetty package (XJetty), a context is exposed to statically access any file located in the webapp/ folder. It allows ac...

  • EPSS 1.64%
  • Veröffentlicht 03.09.2025 20:19:45
  • Zuletzt bearbeitet 10.09.2025 17:24:13

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-2 through 16.10.6, configuration files are accessible through jsx and sx endpoints. It's possible to access and read co...