CVE-2024-55663
- EPSS 1.57%
- Veröffentlicht 12.12.2024 19:15:13
- Zuletzt bearbeitet 10.01.2025 18:02:02
XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 13.10.5 and 14.3-rc-1, in `getdocument.vm`; the ordering of the returned documents is defined from an unsanitized request parameter (request.sort) an...
CVE-2024-55662
- EPSS 44.08%
- Veröffentlicht 12.12.2024 18:15:27
- Zuletzt bearbeitet 30.04.2025 16:03:21
XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is installed, any user can execute any code requiring `programming` rights ...
CVE-2024-46979
- EPSS 0.03%
- Veröffentlicht 18.09.2024 18:15:07
- Zuletzt bearbeitet 07.02.2025 15:39:50
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to get access to notification filters of any user by using a URL such as `<hostname>xwiki/bin/get/XWiki/Notifications/Code/Notifica...
CVE-2024-46978
- EPSS 0.18%
- Veröffentlicht 18.09.2024 18:15:06
- Zuletzt bearbeitet 07.02.2025 15:48:36
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible for any user knowing the ID of a notification filter preference of another user, to enable/disable it or even delete it. The impact...
CVE-2024-45591
- EPSS 48.84%
- Veröffentlicht 10.09.2024 16:15:21
- Zuletzt bearbeitet 20.09.2024 19:55:54
XWiki Platform is a generic wiki platform. The REST API exposes the history of any page in XWiki of which the attacker knows the name. The exposed information includes for each modification of the page the time of the modification, the version number...
CVE-2024-43400
- EPSS 4.27%
- Veröffentlicht 19.08.2024 17:15:09
- Zuletzt bearbeitet 20.08.2024 16:10:29
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script or Programming rights to craft a URL pointing to a page with arbitrary JavaScript. This requires social ...
- EPSS 1.41%
- Veröffentlicht 19.08.2024 17:15:09
- Zuletzt bearbeitet 20.08.2024 16:09:23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor. ...
CVE-2024-41947
- EPSS 7.63%
- Veröffentlicht 31.07.2024 16:15:04
- Zuletzt bearbeitet 06.09.2024 20:46:01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a conflict when another user with more rights is currently editing a page, it is possible to execute JavaScript snippets on the side ...
CVE-2024-37898
- EPSS 0.17%
- Veröffentlicht 31.07.2024 16:15:03
- Zuletzt bearbeitet 06.09.2024 21:16:55
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When a user has view but not edit right on a page in XWiki, that user can delete the page and replace it by a page with new content without havin...
CVE-2024-37900
- EPSS 6.72%
- Veröffentlicht 31.07.2024 16:15:03
- Zuletzt bearbeitet 10.01.2025 16:54:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When uploading an attachment with a malicious filename, malicious JavaScript code could be executed. This requires a social engineering attack to...