Xwiki

Xwiki

239 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 7.42%
  • Published 31.07.2024 16:15:03
  • Last modified 06.09.2024 20:54:20

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit right on any page can perform arbitrary remote code execution by adding instances of `XWiki.SearchSuggestConfig` and `XWiki.Se...

  • EPSS 0.77%
  • Published 24.06.2024 17:15:10
  • Last modified 21.11.2024 09:25:28

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The content of a document included using `{{include reference="targetdocument"/}}` is executed with the right of the includer and not with the ri...

Exploit
  • EPSS 13.69%
  • Published 20.06.2024 23:15:52
  • Last modified 05.02.2025 16:01:02

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an admin disables a user account, the user's profile is executed with the admin's rights. This allows a user to place malicious code in the ...

Exploit
  • EPSS 60.25%
  • Published 10.04.2024 22:15:07
  • Last modified 09.01.2025 19:02:51

XWiki Platform is a generic wiki platform. Prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, parameters of UI extensions are always interpreted as Velocity code and executed with programming rights. Any user with edit right on any document like the ...

Exploit
  • EPSS 33.68%
  • Published 10.04.2024 21:15:07
  • Last modified 21.01.2025 15:35:42

XWiki Platform is a generic wiki platform. Starting in version 6.4-milestone-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, any user who can edit any page like their profile can create a custom skin with a template override that is executed...

Exploit
  • EPSS 10.84%
  • Published 10.04.2024 21:15:07
  • Last modified 09.01.2025 18:54:53

XWiki Platform is a generic wiki platform. Starting in version 13.9-rc-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, when the realtime editor is installed in XWiki, it allows arbitrary remote code execution with the interaction of an admin...

Exploit
  • EPSS 18.38%
  • Published 10.04.2024 21:15:07
  • Last modified 09.01.2025 18:50:19

XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of escaping tool that is used in XWiki doesn't escape `{`, which, when used in certain places, allows XWiki ...

Exploit
  • EPSS 0.34%
  • Published 10.04.2024 21:15:06
  • Last modified 23.01.2025 15:51:52

XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, it is possible to schedule/trigger/unschedule existing jobs by having an admin visit the Job Scheduler page through a predictabl...

Exploit
  • EPSS 10.81%
  • Published 10.04.2024 21:15:06
  • Last modified 21.01.2025 15:43:52

XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, by creating a document with a special crafted documented reference and an `XWiki.SchedulerJobClass` XObject, it is possible to e...

Exploit
  • EPSS 33.68%
  • Published 10.04.2024 20:15:08
  • Last modified 21.01.2025 16:26:42

XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, remote code execution is possible via PDF export templates. This vulnerability has been patched in XWiki 14.10.20, 15.5.4 and ...