CVE-2023-36468
- EPSS 7.19%
- Published 29.06.2023 21:15:09
- Last modified 21.11.2024 08:09:46
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an XWiki installation is upgraded and that upgrade contains a fix for a bug in a document, just a new version of that document is added. In ...
CVE-2023-36469
- EPSS 47.07%
- Published 29.06.2023 21:15:09
- Last modified 21.11.2024 08:09:46
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile and notification settings can execute arbitrary script macros including Groovy and Python macros tha...
CVE-2023-36470
- EPSS 14.17%
- Published 29.06.2023 21:15:09
- Last modified 21.11.2024 08:09:46
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By either creating a new or editing an existing document with an icon set, an attacker can inject XWiki syntax and Velocity code that is executed...
CVE-2023-35155
- EPSS 47.03%
- Published 23.06.2023 19:15:09
- Last modified 21.11.2024 08:08:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). For instance, the following URL execute an `alter`...
CVE-2023-35156
- EPSS 9.28%
- Published 23.06.2023 19:15:09
- Last modified 21.11.2024 08:08:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the delete template to pe...
CVE-2023-35157
- EPSS 1.13%
- Published 23.06.2023 19:15:09
- Last modified 21.11.2024 08:08:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to perform an XSS by forging a request to a delete attachment action with a specific attachment name. Now this XSS can be exploited...
CVE-2023-35158
- EPSS 7.64%
- Published 23.06.2023 19:15:09
- Last modified 21.11.2024 08:08:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the restore template to p...
CVE-2023-35159
- EPSS 3.38%
- Published 23.06.2023 19:15:09
- Last modified 21.11.2024 08:08:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the deletespace template ...
CVE-2023-35160
- EPSS 3.38%
- Published 23.06.2023 19:15:09
- Last modified 21.11.2024 08:08:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the resubmit template to ...
CVE-2023-35161
- EPSS 3.38%
- Published 23.06.2023 19:15:09
- Last modified 21.11.2024 08:08:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the DeleteApplication pag...