CVE-2023-29507
- EPSS 0.65%
- Published 16.04.2023 07:15:53
- Last modified 06.02.2025 17:15:16
XWiki Commons are technical libraries common to several other top level XWiki projects. The Document script API returns directly a DocumentAuthors allowing to set any authors to the document, which in consequence can allow subsequent executions of sc...
CVE-2023-29211
- EPSS 9.47%
- Published 16.04.2023 07:15:52
- Last modified 21.11.2024 07:56:43
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights `WikiManager.DeleteWiki` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation...
CVE-2023-29209
- EPSS 2.55%
- Published 15.04.2023 17:15:07
- Last modified 21.11.2024 07:56:43
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents including the legacy notification activity macro can execute arbitrary Groovy, Python or Velocity code ...
CVE-2023-29210
- EPSS 8.21%
- Published 15.04.2023 17:15:07
- Last modified 21.11.2024 07:56:43
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents including the notification preferences macros can execute arbitrary Groovy, Python or Velocity code in ...
CVE-2023-29203
- EPSS 0.12%
- Published 15.04.2023 16:15:07
- Last modified 21.11.2024 07:56:42
XWiki Commons are technical libraries common to several other top level XWiki projects. It's possible to list some users who are normally not viewable from subwiki by requesting users on a subwiki which allows only global users with `uorgsuggest.vm`....
CVE-2023-29204
- EPSS 9.83%
- Published 15.04.2023 16:15:07
- Last modified 21.11.2024 07:56:42
XWiki Commons are technical libraries common to several other top level XWiki projects. It is possible to bypass the existing security measures put in place to avoid open redirect by using a redirect such as `//mydomain.com` (i.e. omitting the `http:...
CVE-2023-29205
- EPSS 2.31%
- Published 15.04.2023 16:15:07
- Last modified 21.11.2024 07:56:42
XWiki Commons are technical libraries common to several other top level XWiki projects. The HTML macro does not systematically perform a proper neutralization of script-related html tags. As a result, any user able to use the html macro in XWiki, is ...
CVE-2023-29206
- EPSS 6.53%
- Published 15.04.2023 16:15:07
- Last modified 21.11.2024 07:56:42
XWiki Commons are technical libraries common to several other top level XWiki projects. There was no check in the author of a JavaScript xobject or StyleSheet xobject added in a XWiki document, so until now it was possible for a user having only Edit...
- EPSS 2.45%
- Published 15.04.2023 16:15:07
- Last modified 21.11.2024 07:56:42
XWiki Commons are technical libraries common to several other top level XWiki projects. The Livetable Macro wasn't properly sanitizing column names, thus allowing the insertion of raw HTML code including JavaScript. This vulnerability was also explo...
CVE-2023-29208
- EPSS 0.17%
- Published 15.04.2023 16:15:07
- Last modified 21.11.2024 07:56:43
XWiki Commons are technical libraries common to several other top level XWiki projects. Rights added to a document are not taken into account for viewing it once it's deleted. Note that this vulnerability only impact deleted documents that where cont...