CVE-2025-32968
- EPSS 0.17%
- Veröffentlicht 23.04.2025 15:27:27
- Zuletzt bearbeitet 30.04.2025 16:09:17
XWiki is a generic wiki platform. In versions starting from 1.6-milestone-1 to before 15.10.16, 16.4.6, and 16.10.1, it is possible for a user with SCRIPT right to escape from the HQL execution context and perform a blind SQL injection to execute arb...
CVE-2025-32783
- EPSS 0.05%
- Veröffentlicht 16.04.2025 21:38:06
- Zuletzt bearbeitet 30.04.2025 15:56:09
XWiki Platform is a generic wiki platform. A vulnerability in versions from 5.0 to 16.7.1 affects users with Message Stream enabled and a wiki configured as closed from selecting "Prevent unregistered users to view pages" in the Administrations Right...
CVE-2025-29926
- EPSS 1.17%
- Veröffentlicht 19.03.2025 17:40:44
- Zuletzt bearbeitet 13.05.2025 13:34:02
XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager REST API to create a new wiki, where the user could become an administrator and so performs other attacks on the farm. Note that t...
CVE-2025-29925
- EPSS 0.48%
- Veröffentlicht 19.03.2025 17:36:28
- Zuletzt bearbeitet 30.04.2025 15:57:32
XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, protected pages are listed when requesting the REST endpoints /rest/wikis/[wikiName]/pages even if the user doesn't have view rights on them. It's particularly tr...
CVE-2025-29924
- EPSS 0.04%
- Veröffentlicht 19.03.2025 17:31:09
- Zuletzt bearbeitet 30.04.2025 15:58:41
XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, it's possible for an user to get access to private information through the REST API - but could also be through another API - when a sub wiki is using "Prevent un...
CVE-2025-24893
- EPSS 94%
- Veröffentlicht 20.02.2025 20:15:46
- Zuletzt bearbeitet 07.05.2025 18:08:35
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availabi...
- EPSS 3.93%
- Veröffentlicht 14.01.2025 18:16:05
- Zuletzt bearbeitet 13.05.2025 13:34:05
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. NOTE: The Realtime WYSIWYG Editor extension was **experimental**, and thus **not recommended**, in the versions affected by this vulnerability. I...
CVE-2024-55877
- EPSS 63.1%
- Veröffentlicht 12.12.2024 20:15:21
- Zuletzt bearbeitet 30.04.2025 16:02:00
XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5.0, any user with an account can perform arbitrary remote code execution by adding instances of `XWiki.WikiMacroClass` to any page...
CVE-2024-55879
- EPSS 41.33%
- Veröffentlicht 12.12.2024 20:15:21
- Zuletzt bearbeitet 30.04.2025 16:01:22
XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with script rights can perform arbitrary remote code execution by adding instances of `XWiki.ConfigurableClass` to any page. This compr...
CVE-2024-55876
- EPSS 0.16%
- Veröffentlicht 12.12.2024 19:15:14
- Zuletzt bearbeitet 30.04.2025 16:02:40
XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0, any user with an account on the main wiki could run scheduling operations on subwikis. To reproduce, as a user on the main wiki w...