Xwiki

Xwiki

239 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.24%
  • Veröffentlicht 02.03.2023 19:15:11
  • Zuletzt bearbeitet 21.11.2024 07:51:35

XWiki Platform is a generic wiki platform. Starting in version 3.2-m3, users can deduce the content of the password fields by repeated call to `LiveTableResults` and `WikisLiveTableResultsMacros`. The issue can be fixed by upgrading to versions 14.7-...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 02.03.2023 19:15:10
  • Zuletzt bearbeitet 21.11.2024 07:50:40

XWiki Platform is a generic wiki platform. Starting in version 3.0-milestone-1, it's possible to execute a script with the right of another user, provided the target user does not have programming right. The problem has been patched in XWiki 14.8-rc-...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 02.03.2023 18:15:11
  • Zuletzt bearbeitet 21.11.2024 07:51:35

XWiki Platform is a generic wiki platform. Starting in version 6.0, users with write rights can insert well-formed content that is not handled well by the parser. As a consequence, some pages becomes unusable, including the user index (if the page co...

Exploit
  • EPSS 1.2%
  • Veröffentlicht 02.03.2023 18:15:11
  • Zuletzt bearbeitet 21.11.2024 07:51:36

XWiki Platform is a generic wiki platform. Starting in version 12.10, a user without script rights can introduce a stored cross-site scripting by using the Live Data macro. This has been patched in XWiki 14.9, 14.4.7, and 13.10.10. There are no known...

Exploit
  • EPSS 49.26%
  • Veröffentlicht 02.03.2023 18:15:10
  • Zuletzt bearbeitet 21.11.2024 07:51:35

XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script macros via the `newThemeName` request parameter (URL parameter), in combina...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 02.03.2023 18:15:10
  • Zuletzt bearbeitet 21.11.2024 07:51:35

XWiki Platform is a generic wiki platform. Starting in version 14.3-rc-1, `org.xwiki.store.script.TemporaryAttachmentsScriptService#uploadTemporaryAttachment` returns an instance of `com.xpn.xwiki.doc.XWikiAttachment`. This class is not supported to ...

  • EPSS 0.26%
  • Veröffentlicht 23.11.2022 21:15:10
  • Zuletzt bearbeitet 21.11.2024 07:24:05

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to make XWiki create many new schemas and fill them with tables just by using a crafted user identifier in the login form. This may...

  • EPSS 0.12%
  • Veröffentlicht 23.11.2022 21:15:10
  • Zuletzt bearbeitet 21.11.2024 07:24:06

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When the `reset a forgotten password` feature of XWiki was used, the password was then stored in plain text in database. This only concerns XWiki...

Exploit
  • EPSS 2.13%
  • Veröffentlicht 23.11.2022 20:15:10
  • Zuletzt bearbeitet 21.11.2024 07:24:05

xwiki-platform-icon-ui is vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection'). Any user with view rights on commonly accessible documents including the icon picker macro can execute arbitrary Groovy, P...

Exploit
  • EPSS 1.99%
  • Veröffentlicht 23.11.2022 20:15:10
  • Zuletzt bearbeitet 21.11.2024 07:24:06

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on commonly accessible documents including the menu macro can execute arbitrary Groovy, Python or Velocity code in XWik...