CVE-2023-35152
- EPSS 0.91%
- Veröffentlicht 23.06.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:02
XWiki Platform is a generic wiki platform. Starting in version 12.9-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.1, any logged in user can add dangerous content in their first name field and see it executed with programming rights. Leading to r...
CVE-2023-34465
- EPSS 0.55%
- Veröffentlicht 23.06.2023 16:15:09
- Zuletzt bearbeitet 21.11.2024 08:07:18
XWiki Platform is a generic wiki platform. Starting in version 11.8-rc-1 and prior to versions 14.4.8, 14.10.6, and 15.2, `Mail.MailConfig` can be edited by any logged-in user by default. Consequently, they can change the mail obfuscation configurati...
CVE-2023-34466
- EPSS 0.19%
- Veröffentlicht 23.06.2023 16:15:09
- Zuletzt bearbeitet 21.11.2024 08:07:18
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 5.0-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, tags from pages not viewable to the current user are le...
CVE-2023-34464
- EPSS 1.55%
- Veröffentlicht 23.06.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 08:07:18
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.2.1 until versions 14.4.8, 14.10.5, and 15.1RC1 of org.xwiki.platform:xwiki-platform-web and any version prior to 14.4.8, 1...
CVE-2023-35166
- EPSS 30.22%
- Veröffentlicht 20.06.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:08:04
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute any wiki content with the right of the TipsPanel author by creating a tip UI extension. This has been patched in XWiki 1...
CVE-2023-32068
- EPSS 61.12%
- Veröffentlicht 15.05.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 08:02:38
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 14.10.4 it's possible to exploit well known parameters in XWiki URLs to perform redirection to untrusted site. This vulnerab...
CVE-2023-32070
- EPSS 5.39%
- Veröffentlicht 10.05.2023 18:15:10
- Zuletzt bearbeitet 27.01.2025 18:15:35
XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki synta...
CVE-2023-32069
- EPSS 2.97%
- Veröffentlicht 09.05.2023 16:15:15
- Zuletzt bearbeitet 21.11.2024 08:02:39
XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-2 and prior to versions 14.10.4 and 15.0-rc-1, it's possible for a user to execute anything with the right of the author of the XWiki.ClassSheet document. This has been patc...
- EPSS 50.09%
- Veröffentlicht 09.05.2023 16:15:15
- Zuletzt bearbeitet 21.11.2024 08:02:39
XWiki Platform is a generic wiki platform. Starting in versions 2.2-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, it's possible to execute javascript with the right of any user by leading him to a special URL on the wiki targeting...
CVE-2023-31126
- EPSS 3.17%
- Veröffentlicht 09.05.2023 13:15:18
- Zuletzt bearbeitet 28.01.2025 18:15:31
`org.xwiki.commons:xwiki-commons-xml` is an XML library used by the open-source wiki platform XWiki. The HTML sanitizer, introduced in version 14.6-rc-1, allows the injection of arbitrary HTML code and thus cross-site scripting via invalid data attri...