CVE-2022-29258
- EPSS 0.83%
- Published 31.05.2022 17:15:07
- Last modified 21.11.2024 06:58:49
XWiki Platform Filter UI provides a generic user interface to convert from a XWiki Filter input stream to an output stream with settings for each stream. Starting with versions 6.0-milestone-2 and 5.4.4 and prior to versions 12.10.11, 14.0-rc-1, 13.4...
CVE-2022-29251
- EPSS 1.83%
- Published 25.05.2022 21:15:08
- Last modified 21.11.2024 06:58:48
XWiki Platform Flamingo Theme UI is a tool that allows customization and preview of any Flamingo-based skin. Starting with versions 6.2.4 and 6.3-rc-1, a possible cross-site scripting vector is present in the `FlamingoThemesCode.WebHomeSheet` wiki pa...
CVE-2022-29252
- EPSS 0.83%
- Published 25.05.2022 21:15:08
- Last modified 21.11.2024 06:58:48
XWiki Platform Wiki UI Main Wiki is a package for managing subwikis. Starting with version 5.3-milestone-2, XWiki Platform Wiki UI Main Wiki contains a possible cross-site scripting vector in the `WikiManager.JoinWiki ` wiki page related to the "requ...
- EPSS 0.06%
- Published 25.05.2022 21:15:08
- Last modified 21.11.2024 06:58:48
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with version 8.3-rc-1 and prior to versions 12.10.3 and 14.0, one can ask for any file located in the classloader using the template API...
CVE-2022-29161
- EPSS 0.22%
- Published 06.05.2022 00:15:07
- Last modified 21.11.2024 06:58:36
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypto API will generate X509 certificates signed by default using SHA1 with RSA, which is not considered safe anymore for use in certi...
CVE-2022-24897
- EPSS 0.41%
- Published 02.05.2022 22:15:09
- Last modified 21.11.2024 06:51:20
APIs to evaluate content with Velocity is a package for APIs to evaluate content with Velocity. Starting with version 2.3 and prior to 12.6.7, 12.10.3, and 13.0, the velocity scripts are not properly sandboxed against using the Java File API to perfo...
CVE-2022-24819
- EPSS 4.18%
- Published 08.04.2022 20:15:09
- Last modified 21.11.2024 06:51:10
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents related to users of the wiki. The problem has been patched in X...
CVE-2022-24820
- EPSS 0.12%
- Published 08.04.2022 20:15:09
- Last modified 21.11.2024 06:51:10
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents by rendering some velocity documents. The problem has been patc...
CVE-2022-24821
- EPSS 0.7%
- Published 08.04.2022 19:15:08
- Last modified 21.11.2024 06:51:10
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Simple users can create global SSX/JSX without specific rights: in theory only users with Programming Rights should be allowed to create SSX or J...
CVE-2022-23620
- EPSS 0.31%
- Published 09.02.2022 22:15:07
- Last modified 21.11.2024 06:48:57
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions AbstractSxExportURLFactoryActionHandler#processSx does not escape anything from SSX document references when serializing it ...