Xwiki

Xwiki

239 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.65%
  • Veröffentlicht 16.04.2023 07:15:53
  • Zuletzt bearbeitet 06.02.2025 17:15:16

XWiki Commons are technical libraries common to several other top level XWiki projects. The Document script API returns directly a DocumentAuthors allowing to set any authors to the document, which in consequence can allow subsequent executions of sc...

Exploit
  • EPSS 9.47%
  • Veröffentlicht 16.04.2023 07:15:52
  • Zuletzt bearbeitet 21.11.2024 07:56:43

XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights `WikiManager.DeleteWiki` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation...

Exploit
  • EPSS 2.55%
  • Veröffentlicht 15.04.2023 17:15:07
  • Zuletzt bearbeitet 21.11.2024 07:56:43

XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents including the legacy notification activity macro can execute arbitrary Groovy, Python or Velocity code ...

Exploit
  • EPSS 8.21%
  • Veröffentlicht 15.04.2023 17:15:07
  • Zuletzt bearbeitet 21.11.2024 07:56:43

XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents including the notification preferences macros can execute arbitrary Groovy, Python or Velocity code in ...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 15.04.2023 16:15:07
  • Zuletzt bearbeitet 21.11.2024 07:56:42

XWiki Commons are technical libraries common to several other top level XWiki projects. It's possible to list some users who are normally not viewable from subwiki by requesting users on a subwiki which allows only global users with `uorgsuggest.vm`....

Exploit
  • EPSS 9.83%
  • Veröffentlicht 15.04.2023 16:15:07
  • Zuletzt bearbeitet 21.11.2024 07:56:42

XWiki Commons are technical libraries common to several other top level XWiki projects. It is possible to bypass the existing security measures put in place to avoid open redirect by using a redirect such as `//mydomain.com` (i.e. omitting the `http:...

Exploit
  • EPSS 2.31%
  • Veröffentlicht 15.04.2023 16:15:07
  • Zuletzt bearbeitet 21.11.2024 07:56:42

XWiki Commons are technical libraries common to several other top level XWiki projects. The HTML macro does not systematically perform a proper neutralization of script-related html tags. As a result, any user able to use the html macro in XWiki, is ...

Exploit
  • EPSS 6.53%
  • Veröffentlicht 15.04.2023 16:15:07
  • Zuletzt bearbeitet 21.11.2024 07:56:42

XWiki Commons are technical libraries common to several other top level XWiki projects. There was no check in the author of a JavaScript xobject or StyleSheet xobject added in a XWiki document, so until now it was possible for a user having only Edit...

Exploit
  • EPSS 2.45%
  • Veröffentlicht 15.04.2023 16:15:07
  • Zuletzt bearbeitet 21.11.2024 07:56:42

XWiki Commons are technical libraries common to several other top level XWiki projects. The Livetable Macro wasn't properly sanitizing column names, thus allowing the insertion of raw HTML code including JavaScript. This vulnerability was also explo...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 15.04.2023 16:15:07
  • Zuletzt bearbeitet 21.11.2024 07:56:43

XWiki Commons are technical libraries common to several other top level XWiki projects. Rights added to a document are not taken into account for viewing it once it's deleted. Note that this vulnerability only impact deleted documents that where cont...