Xwiki

Xwiki

239 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Published 12.06.2025 14:56:56
  • Last modified 03.09.2025 17:52:50

XWiki is a generic wiki platform. It's possible to execute any SQL query in Oracle by using the function like DBMS_XMLGEN or DBMS_XMLQUERY. The XWiki query validator does not sanitize functions that would be used in a simple select and Hibernate allo...

Exploit
  • EPSS 0.22%
  • Published 30.04.2025 18:27:53
  • Last modified 03.09.2025 17:53:01

XWiki is a generic wiki platform. In versions starting from 1.8.1 to before 14.10.22, from 15.0-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.7.0, anyone can access the metadata of any attachment in the...

  • EPSS 0.13%
  • Published 30.04.2025 18:27:39
  • Last modified 03.09.2025 17:52:56

XWiki is a generic wiki platform. In versions starting from 15.3-rc-1 to before 15.10.14, from 16.0.0-rc-1 to before 16.4.6, and from 16.5.0-rc-1 to before 16.10.0-rc-1, a user who can access pages located in the XWiki space (by default, anyone) can ...

Exploit
  • EPSS 0.85%
  • Published 30.04.2025 18:27:30
  • Last modified 26.08.2025 16:28:44

XWiki Contrib's Syntax Markdown allows importing Markdown content into wiki pages and creating wiki content in Markdown. In versions starting from 8.2 to before 8.9, the Markdown syntax is vulnerable to cross-site scripting (XSS) through HTML. In par...

Exploit
  • EPSS 1.09%
  • Published 30.04.2025 14:55:04
  • Last modified 13.05.2025 14:58:48

XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.8.0-rc-1, when a user with programming rights edits a document in XWiki that was last edite...

  • EPSS 0.69%
  • Published 30.04.2025 14:55:01
  • Last modified 13.05.2025 14:55:03

XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.8 and from 16.0.0-rc-1 to before 16.2.0, the required rights analysis doesn't consider TextAreas with default content type. When editing a page, XWiki warns since v...

  • EPSS 0.06%
  • Published 30.04.2025 14:54:58
  • Last modified 13.05.2025 15:05:07

XWiki is a generic wiki platform. In versions starting from 6.1-milestone-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.8.0-rc-1, the script API of the LESS compiler in XWiki is incorrectly checking for ri...

Exploit
  • EPSS 0.06%
  • Published 30.04.2025 14:54:55
  • Last modified 13.05.2025 15:06:38

XWiki is a generic wiki platform. In versions starting from 4.5.1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0-rc-1, the Solr script service doesn't take dropped programming rights into account. The Sol...

Exploit
  • EPSS 0.2%
  • Published 30.04.2025 14:54:52
  • Last modified 13.05.2025 15:13:38

XWiki is a generic wiki platform. In versions starting from 13.5-rc-1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0, an open redirect vulnerability in the HTML conversion request filter allows attackers ...

Exploit
  • EPSS 34.01%
  • Published 23.04.2025 15:33:03
  • Last modified 30.04.2025 15:50:37

XWiki is a generic wiki platform. In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possible for a remote unauthenticated user to escape from the HQL execution context and perform a blind SQL injection to execute arbitra...