Xwiki

Xwiki

239 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.99%
  • Published 14.07.2025 23:08:34
  • Last modified 26.08.2025 17:52:16

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 4.2-milestone-1 and prior to versions 13.10.11, 14.4.7, and 14.10, the default ...

  • EPSS 1.63%
  • Published 14.07.2025 23:00:35
  • Last modified 26.08.2025 17:52:40

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 5.4.5 and prior to version 14.10, the XHTML syntax depended on the `xdom+xml/cu...

Exploit
  • EPSS 0.19%
  • Published 13.06.2025 17:51:48
  • Last modified 03.09.2025 17:44:02

XWiki is an open-source wiki software platform. When a user without script right creates a document with an XWiki.Notifications.Code.NotificationDisplayerClass object, and later an admin edits and saves that document, the possibly malicious content o...

Exploit
  • EPSS 3.77%
  • Published 13.06.2025 17:47:07
  • Last modified 03.09.2025 17:47:10

XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes application (the default for all users XWiki) can obtain programming right/perform remote code execution by editing the application. Thi...

Exploit
  • EPSS 0.25%
  • Published 13.06.2025 17:33:34
  • Last modified 03.09.2025 17:47:36

XWiki is a generic wiki platform. In versions before 15.10.16, 16.0.0-rc-1 through 16.4.6, and 16.5.0-rc-1 through 16.10.1, when an attacker without script or programming right creates an XClass definition in XWiki (requires edit right), and that sam...

Exploit
  • EPSS 0.04%
  • Published 13.06.2025 17:21:33
  • Last modified 03.09.2025 17:48:29

XWiki is a generic wiki platform. In XWiki Platform versions 10.9 through 16.4.6, 16.5.0-rc-1 through 16.10.2, and 17.0.0-rc-1, the title of every single page whose reference is known can be accessed through the REST API as long as an XClass with a p...

Exploit
  • EPSS 0.02%
  • Published 13.06.2025 17:15:23
  • Last modified 03.09.2025 17:50:20

XWiki is a generic wiki platform. When a user without script right creates a document with an `XWiki.Notifications.Code.NotificationEmailRendererClass` object, and later an admin edits and saves that document, the email templates in this object will ...

Exploit
  • EPSS 0.68%
  • Published 13.06.2025 16:41:45
  • Last modified 03.09.2025 17:50:47

XWiki is a generic wiki platform. When editing content that contains "dangerous" macros like malicious script macros that were authored by a user with fewer rights, XWiki warns about the execution of these macros since XWiki 15.9RC1. These required r...

Exploit
  • EPSS 0.83%
  • Published 13.06.2025 16:09:22
  • Last modified 03.09.2025 17:51:15

XWiki is a generic wiki platform. Any user with edit right on a page (could be the user's profile) can execute code (Groovy, Python, Velocity) with programming right by defining a wiki macro. This allows full access to the whole XWiki installation. T...

Exploit
  • EPSS 0.27%
  • Published 13.06.2025 15:45:58
  • Last modified 03.09.2025 17:52:44

XWiki is a generic wiki platform. From 8.2 and 7.4.5 until 17.1.0-rc-1, 16.10.4, and 16.4.7, pages can gain script or programming rights when they contain a link and the target of the link is renamed or moved. This might lead to execution of scripts ...