CVE-2023-40176
- EPSS 35.14%
- Veröffentlicht 23.08.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 08:18:56
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can exploit a stored XSS through their user profile by setting the payload as the value of the time zone user preference. Eve...
CVE-2023-37914
- EPSS 4.32%
- Veröffentlicht 17.08.2023 18:15:14
- Zuletzt bearbeitet 21.11.2024 08:12:27
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can view `Invitation.WebHome` can execute arbitrary script macros including Groovy and Python macros that allow remote code executio...
CVE-2023-37462
- EPSS 90.26%
- Veröffentlicht 14.07.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 08:11:45
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode.XWikiSkinsSheet` leads to an injection vector from view right on that document to programming rights...
CVE-2023-37277
- EPSS 2.26%
- Veröffentlicht 10.07.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 08:11:22
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The REST API allows executing all actions via POST requests and accepts `text/plain`, `multipart/form-data` or `application/www-form-urlencoded` ...
CVE-2023-36477
- EPSS 2.45%
- Veröffentlicht 30.06.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:09:47
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights can edit all pages in the `CKEditor' space. This makes it possible to perform a variety of harmful actions, such as rem...
CVE-2023-36468
- EPSS 10.28%
- Veröffentlicht 29.06.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 08:09:46
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an XWiki installation is upgraded and that upgrade contains a fix for a bug in a document, just a new version of that document is added. In ...
CVE-2023-36469
- EPSS 47.07%
- Veröffentlicht 29.06.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 08:09:46
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile and notification settings can execute arbitrary script macros including Groovy and Python macros tha...
CVE-2023-36470
- EPSS 14.17%
- Veröffentlicht 29.06.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 08:09:46
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By either creating a new or editing an existing document with an icon set, an attacker can inject XWiki syntax and Velocity code that is executed...
CVE-2023-35155
- EPSS 40.47%
- Veröffentlicht 23.06.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). For instance, the following URL execute an `alter`...
CVE-2023-35156
- EPSS 12.09%
- Veröffentlicht 23.06.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the delete template to pe...