CVE-2024-31982
- EPSS 94.31%
- Published 10.04.2024 20:15:08
- Last modified 25.09.2025 17:15:36
XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's database search allows remote code execution through the search text. This allows remote code execution for ...
CVE-2024-31983
- EPSS 36.26%
- Published 10.04.2024 20:15:08
- Last modified 21.01.2025 16:22:36
XWiki Platform is a generic wiki platform. In multilingual wikis, translations can be edited by any user who has edit right, circumventing the rights that are normally required for authoring translations (script right for user-scope translations, wik...
CVE-2024-31984
- EPSS 66.04%
- Published 10.04.2024 20:15:08
- Last modified 21.01.2025 16:20:37
XWiki Platform is a generic wiki platform. Starting in version 7.2-rc-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, by creating a document with a specially crafted title, it is possible to trigger remote code execution in the (Solr-based) ...
CVE-2024-31465
- EPSS 35.31%
- Published 10.04.2024 20:15:07
- Last modified 09.01.2025 16:49:22
XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.20, 15.5.4, and 15.9-rc-1, any user with edit right on any page can execute any code on the server by adding an object of type `XWiki.SearchSuggestSou...
CVE-2024-31464
- EPSS 0.2%
- Published 10.04.2024 19:15:49
- Last modified 09.01.2025 16:41:19
XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.19, 15.5.4, and 15.9-rc-1, it is possible to access the hash of a password by using the diff feature of the history whenever the object storing the pa...
CVE-2024-21648
- EPSS 0.34%
- Published 09.01.2024 00:15:44
- Last modified 21.11.2024 08:54:47
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The rollback action is missing a right protection, a user can rollback to a previous version of the page to gain rights they don't have anymore. ...
CVE-2024-21651
- EPSS 0.38%
- Published 09.01.2024 00:15:44
- Last modified 21.11.2024 08:54:48
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to attach a file to a page can post a malformed TAR file by manipulating file modification times headers, which when parsed by Tika, ...
CVE-2024-21650
- EPSS 92.89%
- Published 08.01.2024 16:15:46
- Last modified 21.11.2024 08:54:48
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code execution (RCE) attack through its user registration feature. This issue allows an attacker to execute arbit...
CVE-2023-50732
- EPSS 1.36%
- Published 21.12.2023 20:15:07
- Last modified 21.11.2024 08:37:14
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute a Velocity script without script right through the document tree. This has been patched in XWiki 14.10.7 and 15.2RC1.
CVE-2023-50723
- EPSS 5.39%
- Published 15.12.2023 19:15:10
- Last modified 21.11.2024 08:37:12
XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, anyone who can edit an arbitrary wiki page in an XWiki installation can gain programming right through several cases of missing escaping...