CVE-2023-37913
- EPSS 3.73%
- Published 25.10.2023 18:17:28
- Last modified 21.11.2024 08:12:27
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 3.5-milestone-1 and prior to versions 14.10.8 and 15.3-rc-1, triggering the office converter with a specially crafted file na...
CVE-2023-41046
- EPSS 0.1%
- Published 01.09.2023 20:15:07
- Last modified 21.11.2024 08:20:27
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible in XWiki to execute Velocity code without having script right by creating an XClass with a property of type "TextArea" and content...
- EPSS 1.8%
- Published 24.08.2023 02:15:09
- Last modified 21.11.2024 08:19:44
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The create action is vulnerable to a CSRF attack, allowing script and thus remote code execution when targeting a user with script/programming ri...
CVE-2023-40573
- EPSS 3.52%
- Published 24.08.2023 02:15:09
- Last modified 21.11.2024 08:19:44
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki supports scheduled jobs that contain Groovy scripts. Currently, the job checks the content author of the job for programming right. However...
CVE-2023-40177
- EPSS 2.11%
- Published 23.08.2023 21:15:08
- Last modified 21.11.2024 08:18:56
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can use the content field of their user profile page to execute arbitrary scripts with programming rights, thus effectively p...
CVE-2023-40176
- EPSS 32.09%
- Published 23.08.2023 20:15:08
- Last modified 21.11.2024 08:18:56
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can exploit a stored XSS through their user profile by setting the payload as the value of the time zone user preference. Eve...
CVE-2023-37914
- EPSS 4.32%
- Published 17.08.2023 18:15:14
- Last modified 21.11.2024 08:12:27
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can view `Invitation.WebHome` can execute arbitrary script macros including Groovy and Python macros that allow remote code executio...
CVE-2023-37462
- EPSS 91.45%
- Published 14.07.2023 21:15:08
- Last modified 21.11.2024 08:11:45
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode.XWikiSkinsSheet` leads to an injection vector from view right on that document to programming rights...
CVE-2023-37277
- EPSS 2.26%
- Published 10.07.2023 17:15:09
- Last modified 21.11.2024 08:11:22
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The REST API allows executing all actions via POST requests and accepts `text/plain`, `multipart/form-data` or `application/www-form-urlencoded` ...
CVE-2023-36477
- EPSS 1.82%
- Published 30.06.2023 19:15:09
- Last modified 21.11.2024 08:09:47
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights can edit all pages in the `CKEditor' space. This makes it possible to perform a variety of harmful actions, such as rem...