Xwiki

Xwiki

239 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.38%
  • Published 23.06.2023 19:15:09
  • Last modified 21.11.2024 08:08:04

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the previewactions templa...

Exploit
  • EPSS 2.09%
  • Published 23.06.2023 18:15:13
  • Last modified 21.11.2024 08:08:02

XWiki Platform is a generic wiki platform. Starting in version 5.4.4 and prior to versions 14.4.8, 14.10.4, and 15.0, a stored cross-site scripting vulnerability can be exploited by users with edit rights by adding a `AppWithinMinutes.FormFieldCatego...

Exploit
  • EPSS 1.61%
  • Published 23.06.2023 17:15:09
  • Last modified 21.11.2024 08:07:19

XWiki Platform is a generic wiki platform. Starting in version 3.5-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, the mail obfuscation configuration was not fully taken into account. While the mail displayed to the end user was obf...

Exploit
  • EPSS 33.48%
  • Published 23.06.2023 17:15:09
  • Last modified 21.11.2024 08:08:02

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to versions 14.4.8, 14.10.4, and 15.0, any user with view rights on any document can execute code with prog...

  • EPSS 0.21%
  • Published 23.06.2023 17:15:09
  • Last modified 21.11.2024 08:08:02

XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obfuscated passwords, even when the mail obfuscation is activated. The iss...

  • EPSS 0.91%
  • Published 23.06.2023 17:15:09
  • Last modified 21.11.2024 08:08:02

XWiki Platform is a generic wiki platform. Starting in version 12.9-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.1, any logged in user can add dangerous content in their first name field and see it executed with programming rights. Leading to r...

Exploit
  • EPSS 0.55%
  • Published 23.06.2023 16:15:09
  • Last modified 21.11.2024 08:07:18

XWiki Platform is a generic wiki platform. Starting in version 11.8-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.2, `Mail.MailConfig` can be edited by any logged-in user by default. Consequently, they can change the mail obfuscation configurati...

Exploit
  • EPSS 0.19%
  • Published 23.06.2023 16:15:09
  • Last modified 21.11.2024 08:07:18

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 5.0-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, tags from pages not viewable to the current user are le...

Exploit
  • EPSS 1.55%
  • Published 23.06.2023 15:15:09
  • Last modified 21.11.2024 08:07:18

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.2.1 until versions 14.4.8, 14.10.5, and 15.1RC1 of org.xwiki.platform:xwiki-platform-web and any version prior to 14.4.8, 1...

Exploit
  • EPSS 30.22%
  • Published 20.06.2023 20:15:09
  • Last modified 21.11.2024 08:08:04

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute any wiki content with the right of the TipsPanel author by creating a tip UI extension. This has been patched in XWiki 1...