CVE-2024-37901
- EPSS 7.42%
- Veröffentlicht 31.07.2024 16:15:03
- Zuletzt bearbeitet 06.09.2024 20:54:20
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit right on any page can perform arbitrary remote code execution by adding instances of `XWiki.SearchSuggestConfig` and `XWiki.Se...
CVE-2024-38369
- EPSS 0.77%
- Veröffentlicht 24.06.2024 17:15:10
- Zuletzt bearbeitet 21.11.2024 09:25:28
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The content of a document included using `{{include reference="targetdocument"/}}` is executed with the right of the includer and not with the ri...
- EPSS 13.69%
- Veröffentlicht 20.06.2024 23:15:52
- Zuletzt bearbeitet 05.02.2025 16:01:02
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an admin disables a user account, the user's profile is executed with the admin's rights. This allows a user to place malicious code in the ...
CVE-2024-31997
- EPSS 60.25%
- Veröffentlicht 10.04.2024 22:15:07
- Zuletzt bearbeitet 09.01.2025 19:02:51
XWiki Platform is a generic wiki platform. Prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, parameters of UI extensions are always interpreted as Velocity code and executed with programming rights. Any user with edit right on any document like the ...
CVE-2024-31987
- EPSS 33.68%
- Veröffentlicht 10.04.2024 21:15:07
- Zuletzt bearbeitet 21.01.2025 15:35:42
XWiki Platform is a generic wiki platform. Starting in version 6.4-milestone-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, any user who can edit any page like their profile can create a custom skin with a template override that is executed...
CVE-2024-31988
- EPSS 10.84%
- Veröffentlicht 10.04.2024 21:15:07
- Zuletzt bearbeitet 09.01.2025 18:54:53
XWiki Platform is a generic wiki platform. Starting in version 13.9-rc-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, when the realtime editor is installed in XWiki, it allows arbitrary remote code execution with the interaction of an admin...
CVE-2024-31996
- EPSS 18.38%
- Veröffentlicht 10.04.2024 21:15:07
- Zuletzt bearbeitet 09.01.2025 18:50:19
XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of escaping tool that is used in XWiki doesn't escape `{`, which, when used in certain places, allows XWiki ...
CVE-2024-31985
- EPSS 0.34%
- Veröffentlicht 10.04.2024 21:15:06
- Zuletzt bearbeitet 23.01.2025 15:51:52
XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, it is possible to schedule/trigger/unschedule existing jobs by having an admin visit the Job Scheduler page through a predictabl...
CVE-2024-31986
- EPSS 10.81%
- Veröffentlicht 10.04.2024 21:15:06
- Zuletzt bearbeitet 21.01.2025 15:43:52
XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, by creating a document with a special crafted documented reference and an `XWiki.SchedulerJobClass` XObject, it is possible to e...
CVE-2024-31981
- EPSS 33.68%
- Veröffentlicht 10.04.2024 20:15:08
- Zuletzt bearbeitet 21.01.2025 16:26:42
XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, remote code execution is possible via PDF export templates. This vulnerability has been patched in XWiki 14.10.20, 15.5.4 and ...