CVE-2023-50719
- EPSS 46.28%
- Veröffentlicht 15.12.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:37:12
XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password hashes of all users to anyone with view right on the respective user p...
CVE-2023-50720
- EPSS 51.4%
- Veröffentlicht 15.12.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:37:12
XWiki Platform is a generic wiki platform. Prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the email addresses of users even when obfuscation of email addresses is enabled. To demonstrate the vulnerability,...
CVE-2023-50721
- EPSS 43.25%
- Veröffentlicht 15.12.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:37:12
XWiki Platform is a generic wiki platform. Starting in 4.5-rc-1 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the search administration interface doesn't properly escape the id and label of search user interface extensions, allowing the inje...
CVE-2023-50722
- EPSS 3.26%
- Veröffentlicht 15.12.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:37:12
XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, there is a reflected XSS or also direct remote code execution vulnerability in the code for displaying configurable admin sections. The ...
CVE-2023-48293
- EPSS 0.76%
- Veröffentlicht 20.11.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:31:25
The XWiki Admin Tools Application provides tools to help the administration of XWiki. Prior to version 4.5.1, a cross-site request forgery vulnerability in the query on XWiki tool allows executing arbitrary database queries on the database of the XWi...
CVE-2023-48240
- EPSS 1.58%
- Veröffentlicht 20.11.2023 18:15:07
- Zuletzt bearbeitet 21.11.2024 08:31:17
XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents and not display a difference for an actually unchanged image. For this, XWiki requests all embedded images on the server side. Thes...
CVE-2023-48241
- EPSS 68.26%
- Veröffentlicht 20.11.2023 18:15:07
- Zuletzt bearbeitet 21.11.2024 08:31:17
XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, and 15.6RC1, the Solr-based search suggestion provider that also duplicates as generic JavaScript API for search results in XWiki e...
CVE-2023-46243
- EPSS 7.48%
- Veröffentlicht 07.11.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 08:28:09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a user to execute any content with the right of an existing document's content author, provided the user h...
CVE-2023-46242
- EPSS 3.25%
- Veröffentlicht 07.11.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 08:28:09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to execute a content with the right of any user via a crafted URL. A user must have `programming` privileges i...
CVE-2023-46244
- EPSS 1.42%
- Veröffentlicht 07.11.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 08:28:09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a user to write a script in which any velocity content is executed with the right of any other document co...