CVE-2023-32068
- EPSS 65.03%
- Veröffentlicht 15.05.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 08:02:38
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 14.10.4 it's possible to exploit well known parameters in XWiki URLs to perform redirection to untrusted site. This vulnerab...
CVE-2023-32070
- EPSS 4.17%
- Veröffentlicht 10.05.2023 18:15:10
- Zuletzt bearbeitet 27.01.2025 18:15:35
XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki synta...
CVE-2023-32069
- EPSS 3.06%
- Veröffentlicht 09.05.2023 16:15:15
- Zuletzt bearbeitet 21.11.2024 08:02:39
XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-2 and prior to versions 14.10.4 and 15.0-rc-1, it's possible for a user to execute anything with the right of the author of the XWiki.ClassSheet document. This has been patc...
- EPSS 52.99%
- Veröffentlicht 09.05.2023 16:15:15
- Zuletzt bearbeitet 21.11.2024 08:02:39
XWiki Platform is a generic wiki platform. Starting in versions 2.2-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, it's possible to execute javascript with the right of any user by leading him to a special URL on the wiki targeting...
CVE-2023-31126
- EPSS 3.27%
- Veröffentlicht 09.05.2023 13:15:18
- Zuletzt bearbeitet 28.01.2025 18:15:31
`org.xwiki.commons:xwiki-commons-xml` is an XML library used by the open-source wiki platform XWiki. The HTML sanitizer, introduced in version 14.6-rc-1, allows the injection of arbitrary HTML code and thus cross-site scripting via invalid data attri...
CVE-2023-29524
- EPSS 42.2%
- Veröffentlicht 19.04.2023 00:15:09
- Zuletzt bearbeitet 21.11.2024 07:57:13
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute anything with the right of the Scheduler Application sheet page. A user without script or programming rights, edit your ...
CVE-2023-29525
- EPSS 24.03%
- Veröffentlicht 19.04.2023 00:15:09
- Zuletzt bearbeitet 21.11.2024 07:57:13
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Affected versions of xwiki are subject to code injection in the `since` parameter of the `/xwiki/bin/view/XWiki/Notifications/Code/LegacyNotifica...
CVE-2023-29526
- EPSS 2.68%
- Veröffentlicht 19.04.2023 00:15:09
- Zuletzt bearbeitet 21.11.2024 07:57:14
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to display or interact with any page a user cannot access through the combination of the async and display mac...
CVE-2023-29527
- EPSS 0.64%
- Veröffentlicht 19.04.2023 00:15:09
- Zuletzt bearbeitet 21.11.2024 07:57:14
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions a user without script or programming right may edit a user profile (or any other document) with the wiki editor and add groo...
CVE-2023-29510
- EPSS 3.02%
- Veröffentlicht 19.04.2023 00:15:08
- Zuletzt bearbeitet 21.11.2024 07:57:12
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In XWiki, every user can add translations that are only applied to the current user. This also allows overriding existing translations. Such tran...