Xwiki

Xwiki

244 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 9.73%
  • Veröffentlicht 15.04.2023 16:15:07
  • Zuletzt bearbeitet 21.11.2024 07:56:42

XWiki Commons are technical libraries common to several other top level XWiki projects. It is possible to bypass the existing security measures put in place to avoid open redirect by using a redirect such as `//mydomain.com` (i.e. omitting the `http:...

Exploit
  • EPSS 3.48%
  • Veröffentlicht 15.04.2023 16:15:07
  • Zuletzt bearbeitet 21.11.2024 07:56:42

XWiki Commons are technical libraries common to several other top level XWiki projects. The HTML macro does not systematically perform a proper neutralization of script-related html tags. As a result, any user able to use the html macro in XWiki, is ...

Exploit
  • EPSS 5.5%
  • Veröffentlicht 15.04.2023 16:15:07
  • Zuletzt bearbeitet 21.11.2024 07:56:42

XWiki Commons are technical libraries common to several other top level XWiki projects. There was no check in the author of a JavaScript xobject or StyleSheet xobject added in a XWiki document, so until now it was possible for a user having only Edit...

Exploit
  • EPSS 2.14%
  • Veröffentlicht 15.04.2023 16:15:07
  • Zuletzt bearbeitet 21.11.2024 07:56:42

XWiki Commons are technical libraries common to several other top level XWiki projects. The Livetable Macro wasn't properly sanitizing column names, thus allowing the insertion of raw HTML code including JavaScript. This vulnerability was also explo...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 15.04.2023 16:15:07
  • Zuletzt bearbeitet 21.11.2024 07:56:43

XWiki Commons are technical libraries common to several other top level XWiki projects. Rights added to a document are not taken into account for viewing it once it's deleted. Note that this vulnerability only impact deleted documents that where cont...

Exploit
  • EPSS 2.33%
  • Veröffentlicht 15.04.2023 15:15:08
  • Zuletzt bearbeitet 21.11.2024 07:56:42

XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1, only escaped `<script>` and `<style>`-tags but neither attributes that ...

Exploit
  • EPSS 2.11%
  • Veröffentlicht 15.04.2023 15:15:08
  • Zuletzt bearbeitet 21.11.2024 07:56:42

XWiki Commons are technical libraries common to several other top level XWiki projects. The RSS macro that is bundled in XWiki included the content of the feed items without any cleaning in the HTML output when the parameter `content` was set to `tru...

Exploit
  • EPSS 1.78%
  • Veröffentlicht 07.03.2023 19:15:12
  • Zuletzt bearbeitet 21.11.2024 07:52:59

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki...

Exploit
  • EPSS 1.26%
  • Veröffentlicht 07.03.2023 19:15:12
  • Zuletzt bearbeitet 21.11.2024 07:52:59

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit rights on a document can trigger an XAR import on a forged XAR file, leading to the ability to display th...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 02.03.2023 19:15:11
  • Zuletzt bearbeitet 21.11.2024 07:51:34

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to make the farm unusable by adding an object to a page with a huge number (e.g. 67108863). Most of the time this will fill the mem...