Xwiki

Xwiki

239 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 65.03%
  • Published 15.05.2023 21:15:09
  • Last modified 21.11.2024 08:02:38

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 14.10.4 it's possible to exploit well known parameters in XWiki URLs to perform redirection to untrusted site. This vulnerab...

  • EPSS 4.17%
  • Published 10.05.2023 18:15:10
  • Last modified 27.01.2025 18:15:35

XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki synta...

  • EPSS 3.06%
  • Published 09.05.2023 16:15:15
  • Last modified 21.11.2024 08:02:39

XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-2 and prior to versions 14.10.4 and 15.0-rc-1, it's possible for a user to execute anything with the right of the author of the XWiki.ClassSheet document. This has been patc...

  • EPSS 52.99%
  • Published 09.05.2023 16:15:15
  • Last modified 21.11.2024 08:02:39

XWiki Platform is a generic wiki platform. Starting in versions 2.2-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, it's possible to execute javascript with the right of any user by leading him to a special URL on the wiki targeting...

  • EPSS 3.27%
  • Published 09.05.2023 13:15:18
  • Last modified 28.01.2025 18:15:31

`org.xwiki.commons:xwiki-commons-xml` is an XML library used by the open-source wiki platform XWiki. The HTML sanitizer, introduced in version 14.6-rc-1, allows the injection of arbitrary HTML code and thus cross-site scripting via invalid data attri...

Exploit
  • EPSS 42.2%
  • Published 19.04.2023 00:15:09
  • Last modified 21.11.2024 07:57:13

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute anything with the right of the Scheduler Application sheet page. A user without script or programming rights, edit your ...

Exploit
  • EPSS 24.03%
  • Published 19.04.2023 00:15:09
  • Last modified 21.11.2024 07:57:13

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Affected versions of xwiki are subject to code injection in the `since` parameter of the `/xwiki/bin/view/XWiki/Notifications/Code/LegacyNotifica...

Exploit
  • EPSS 2.68%
  • Published 19.04.2023 00:15:09
  • Last modified 21.11.2024 07:57:14

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to display or interact with any page a user cannot access through the combination of the async and display mac...

Exploit
  • EPSS 0.64%
  • Published 19.04.2023 00:15:09
  • Last modified 21.11.2024 07:57:14

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions a user without script or programming right may edit a user profile (or any other document) with the wiki editor and add groo...

Exploit
  • EPSS 3.02%
  • Published 19.04.2023 00:15:08
  • Last modified 21.11.2024 07:57:12

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In XWiki, every user can add translations that are only applied to the current user. This also allows overriding existing translations. Such tran...