CVE-2022-36100
- EPSS 6.27%
- Published 08.09.2022 21:15:08
- Last modified 21.11.2024 07:12:23
XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Starting with version 1.7 in XWiki Platform Applications Tag and prior to 13.10.6 and 14.4 in XWiki Platform Tag UI, the tags document ...
CVE-2022-36095
- EPSS 0.11%
- Published 08.09.2022 21:15:07
- Last modified 21.11.2024 07:12:22
XWiki Platform is a generic wiki platform. Prior to versions 13.10.5 and 14.3, it is possible to perform a Cross-Site Request Forgery (CSRF) attack for adding or removing tags on XWiki pages. The problem has been patched in XWiki 13.10.5 and 14.3. As...
- EPSS 54.51%
- Published 08.09.2022 21:15:07
- Last modified 21.11.2024 07:12:22
The XWiki Platform Index UI is an Index of all pages, attachments, orphans and deleted pages and attachments for XWiki Platform, a generic wiki platform. Prior to versions 13.10.6 and 14.3, it's possible to store JavaScript which will be executed by ...
- EPSS 49.21%
- Published 08.09.2022 20:15:08
- Last modified 21.11.2024 07:12:22
XWiki Platform Web Parent POM contains Web resources for the XWiki platform, a generic wiki platform. Starting with version 1.0 and prior to versions 13.10.6 and 14.30-rc-1, it's possible to store JavaScript which will be executed by anyone viewing t...
CVE-2022-36092
- EPSS 0.29%
- Published 08.09.2022 18:15:08
- Last modified 21.11.2024 07:12:22
XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 14.2 and 13.10.4, all rights checks that would normally prevent a user from viewing a document on a wiki can be bypassed using the login action a...
CVE-2022-36093
- EPSS 4.5%
- Published 08.09.2022 18:15:08
- Last modified 21.11.2024 07:12:22
XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. By passing a template of the distribution wizard to the xpart template, user accounts can be created even when user registration is disabled. This also circumvent...
CVE-2022-36091
- EPSS 0.45%
- Published 08.09.2022 16:15:08
- Last modified 21.11.2024 07:12:21
XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. Through the suggestion feature, string and list properties of objects the user shouldn't have access to can be accessed in versions prior to 13.10.4 and 14.2. Thi...
CVE-2022-36090
- EPSS 1.33%
- Published 08.09.2022 15:15:07
- Last modified 21.11.2024 07:12:21
XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 13.1.0.5 and 14.3-rc-1, some resources are missing a check for inactive (not yet activated or disabled) users in XWiki, including the REST servic...
CVE-2022-31166
- EPSS 2%
- Published 07.09.2022 14:15:08
- Last modified 21.11.2024 07:04:02
XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Starting in versions 11.3.7, 11.0.3, and 12.0RC1, it is possible to exploit a bug in XWikiRights resolution of groups to obtain privilege escalation. More specific...
CVE-2022-31167
- EPSS 0.49%
- Published 07.09.2022 14:15:08
- Last modified 21.11.2024 07:04:02
XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with version 5.0 and prior to 12.10.11, 13.10.1, and 13.4.6, a bug in the security cache stores rules associated to document Page1.Pag...