Xwiki

Xwiki

239 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.97%
  • Veröffentlicht 15.04.2023 15:15:08
  • Zuletzt bearbeitet 21.11.2024 07:56:42

XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1, only escaped `<script>` and `<style>`-tags but neither attributes that ...

Exploit
  • EPSS 2.41%
  • Veröffentlicht 15.04.2023 15:15:08
  • Zuletzt bearbeitet 21.11.2024 07:56:42

XWiki Commons are technical libraries common to several other top level XWiki projects. The RSS macro that is bundled in XWiki included the content of the feed items without any cleaning in the HTML output when the parameter `content` was set to `tru...

Exploit
  • EPSS 1.6%
  • Veröffentlicht 07.03.2023 19:15:12
  • Zuletzt bearbeitet 21.11.2024 07:52:59

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki...

Exploit
  • EPSS 1.01%
  • Veröffentlicht 07.03.2023 19:15:12
  • Zuletzt bearbeitet 21.11.2024 07:52:59

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit rights on a document can trigger an XAR import on a forged XAR file, leading to the ability to display th...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 02.03.2023 19:15:11
  • Zuletzt bearbeitet 21.11.2024 07:51:34

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to make the farm unusable by adding an object to a page with a huge number (e.g. 67108863). Most of the time this will fill the mem...

Exploit
  • EPSS 1.74%
  • Veröffentlicht 02.03.2023 19:15:11
  • Zuletzt bearbeitet 21.11.2024 07:51:34

XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the right of superadmin but in restricted mode (anything dangerous is disabled), but the async macro does not take into account the re...

Exploit
  • EPSS 1.42%
  • Veröffentlicht 02.03.2023 19:15:11
  • Zuletzt bearbeitet 21.11.2024 07:51:34

XWiki Platform is a generic wiki platform. Starting in version 6.2-milestone-1, one can execute any wiki content with the right of IconThemeSheet author by creating an icon theme with certain content. This can be done by creating a new page or even t...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 02.03.2023 19:15:11
  • Zuletzt bearbeitet 21.11.2024 07:51:34

XWiki Platform is a generic wiki platform. Starting in version 1.3-rc-1, any user with edit right can execute arbitrary database select and access data stored in the database. The problem has been patched in XWiki 13.10.11, 14.4.7, and 14.10. There i...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 02.03.2023 19:15:11
  • Zuletzt bearbeitet 21.11.2024 07:51:35

XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing document content author to execute a text area property. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11. There are no know...

Exploit
  • EPSS 29.36%
  • Veröffentlicht 02.03.2023 19:15:11
  • Zuletzt bearbeitet 21.11.2024 07:51:35

XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted context. This allows executing anything with the right of the author of any document by annotating t...