CVE-2025-53836
- EPSS 1.99%
- Published 14.07.2025 23:08:34
- Last modified 26.08.2025 17:52:16
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 4.2-milestone-1 and prior to versions 13.10.11, 14.4.7, and 14.10, the default ...
- EPSS 1.63%
- Published 14.07.2025 23:00:35
- Last modified 26.08.2025 17:52:40
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 5.4.5 and prior to version 14.10, the XHTML syntax depended on the `xdom+xml/cu...
- EPSS 0.19%
- Published 13.06.2025 17:51:48
- Last modified 03.09.2025 17:44:02
XWiki is an open-source wiki software platform. When a user without script right creates a document with an XWiki.Notifications.Code.NotificationDisplayerClass object, and later an admin edits and saves that document, the possibly malicious content o...
CVE-2025-49586
- EPSS 3.77%
- Published 13.06.2025 17:47:07
- Last modified 03.09.2025 17:47:10
XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes application (the default for all users XWiki) can obtain programming right/perform remote code execution by editing the application. Thi...
- EPSS 0.25%
- Published 13.06.2025 17:33:34
- Last modified 03.09.2025 17:47:36
XWiki is a generic wiki platform. In versions before 15.10.16, 16.0.0-rc-1 through 16.4.6, and 16.5.0-rc-1 through 16.10.1, when an attacker without script or programming right creates an XClass definition in XWiki (requires edit right), and that sam...
CVE-2025-49584
- EPSS 0.04%
- Published 13.06.2025 17:21:33
- Last modified 03.09.2025 17:48:29
XWiki is a generic wiki platform. In XWiki Platform versions 10.9 through 16.4.6, 16.5.0-rc-1 through 16.10.2, and 17.0.0-rc-1, the title of every single page whose reference is known can be accessed through the REST API as long as an XClass with a p...
CVE-2025-49583
- EPSS 0.02%
- Published 13.06.2025 17:15:23
- Last modified 03.09.2025 17:50:20
XWiki is a generic wiki platform. When a user without script right creates a document with an `XWiki.Notifications.Code.NotificationEmailRendererClass` object, and later an admin edits and saves that document, the email templates in this object will ...
- EPSS 0.68%
- Published 13.06.2025 16:41:45
- Last modified 03.09.2025 17:50:47
XWiki is a generic wiki platform. When editing content that contains "dangerous" macros like malicious script macros that were authored by a user with fewer rights, XWiki warns about the execution of these macros since XWiki 15.9RC1. These required r...
CVE-2025-49581
- EPSS 0.83%
- Published 13.06.2025 16:09:22
- Last modified 03.09.2025 17:51:15
XWiki is a generic wiki platform. Any user with edit right on a page (could be the user's profile) can execute code (Groovy, Python, Velocity) with programming right by defining a wiki macro. This allows full access to the whole XWiki installation. T...
- EPSS 0.27%
- Published 13.06.2025 15:45:58
- Last modified 03.09.2025 17:52:44
XWiki is a generic wiki platform. From 8.2 and 7.4.5 until 17.1.0-rc-1, 16.10.4, and 16.4.7, pages can gain script or programming rights when they contain a link and the target of the link is renamed or moved. This might lead to execution of scripts ...