- EPSS 1.97%
- Published 15.04.2023 15:15:08
- Last modified 21.11.2024 07:56:42
XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1, only escaped `<script>` and `<style>`-tags but neither attributes that ...
- EPSS 2.41%
- Published 15.04.2023 15:15:08
- Last modified 21.11.2024 07:56:42
XWiki Commons are technical libraries common to several other top level XWiki projects. The RSS macro that is bundled in XWiki included the content of the feed items without any cleaning in the HTML output when the parameter `content` was set to `tru...
CVE-2023-27479
- EPSS 1.6%
- Published 07.03.2023 19:15:12
- Last modified 21.11.2024 07:52:59
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki...
CVE-2023-27480
- EPSS 1.01%
- Published 07.03.2023 19:15:12
- Last modified 21.11.2024 07:52:59
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit rights on a document can trigger an XAR import on a forged XAR file, leading to the ability to display th...
CVE-2023-26470
- EPSS 0.2%
- Published 02.03.2023 19:15:11
- Last modified 21.11.2024 07:51:34
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to make the farm unusable by adding an object to a page with a huge number (e.g. 67108863). Most of the time this will fill the mem...
CVE-2023-26471
- EPSS 1.74%
- Published 02.03.2023 19:15:11
- Last modified 21.11.2024 07:51:34
XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the right of superadmin but in restricted mode (anything dangerous is disabled), but the async macro does not take into account the re...
CVE-2023-26472
- EPSS 1.42%
- Published 02.03.2023 19:15:11
- Last modified 21.11.2024 07:51:34
XWiki Platform is a generic wiki platform. Starting in version 6.2-milestone-1, one can execute any wiki content with the right of IconThemeSheet author by creating an icon theme with certain content. This can be done by creating a new page or even t...
CVE-2023-26473
- EPSS 0.12%
- Published 02.03.2023 19:15:11
- Last modified 21.11.2024 07:51:34
XWiki Platform is a generic wiki platform. Starting in version 1.3-rc-1, any user with edit right can execute arbitrary database select and access data stored in the database. The problem has been patched in XWiki 13.10.11, 14.4.7, and 14.10. There i...
CVE-2023-26474
- EPSS 0.36%
- Published 02.03.2023 19:15:11
- Last modified 21.11.2024 07:51:35
XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing document content author to execute a text area property. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11. There are no know...
CVE-2023-26475
- EPSS 29.36%
- Published 02.03.2023 19:15:11
- Last modified 21.11.2024 07:51:35
XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted context. This allows executing anything with the right of the author of any document by annotating t...