Xwiki

Xwiki

239 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.24%
  • Published 02.03.2023 19:15:11
  • Last modified 21.11.2024 07:51:35

XWiki Platform is a generic wiki platform. Starting in version 3.2-m3, users can deduce the content of the password fields by repeated call to `LiveTableResults` and `WikisLiveTableResultsMacros`. The issue can be fixed by upgrading to versions 14.7-...

Exploit
  • EPSS 0.22%
  • Published 02.03.2023 19:15:10
  • Last modified 21.11.2024 07:50:40

XWiki Platform is a generic wiki platform. Starting in version 3.0-milestone-1, it's possible to execute a script with the right of another user, provided the target user does not have programming right. The problem has been patched in XWiki 14.8-rc-...

Exploit
  • EPSS 0.14%
  • Published 02.03.2023 18:15:11
  • Last modified 21.11.2024 07:51:35

XWiki Platform is a generic wiki platform. Starting in version 6.0, users with write rights can insert well-formed content that is not handled well by the parser. As a consequence, some pages becomes unusable, including the user index (if the page co...

Exploit
  • EPSS 1.2%
  • Published 02.03.2023 18:15:11
  • Last modified 21.11.2024 07:51:36

XWiki Platform is a generic wiki platform. Starting in version 12.10, a user without script rights can introduce a stored cross-site scripting by using the Live Data macro. This has been patched in XWiki 14.9, 14.4.7, and 13.10.10. There are no known...

Exploit
  • EPSS 49.26%
  • Published 02.03.2023 18:15:10
  • Last modified 21.11.2024 07:51:35

XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script macros via the `newThemeName` request parameter (URL parameter), in combina...

Exploit
  • EPSS 0.35%
  • Published 02.03.2023 18:15:10
  • Last modified 21.11.2024 07:51:35

XWiki Platform is a generic wiki platform. Starting in version 14.3-rc-1, `org.xwiki.store.script.TemporaryAttachmentsScriptService#uploadTemporaryAttachment` returns an instance of `com.xpn.xwiki.doc.XWikiAttachment`. This class is not supported to ...

  • EPSS 0.26%
  • Published 23.11.2022 21:15:10
  • Last modified 21.11.2024 07:24:05

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to make XWiki create many new schemas and fill them with tables just by using a crafted user identifier in the login form. This may...

  • EPSS 0.12%
  • Published 23.11.2022 21:15:10
  • Last modified 21.11.2024 07:24:06

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When the `reset a forgotten password` feature of XWiki was used, the password was then stored in plain text in database. This only concerns XWiki...

Exploit
  • EPSS 2.13%
  • Published 23.11.2022 20:15:10
  • Last modified 21.11.2024 07:24:05

xwiki-platform-icon-ui is vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection'). Any user with view rights on commonly accessible documents including the icon picker macro can execute arbitrary Groovy, P...

Exploit
  • EPSS 1.99%
  • Published 23.11.2022 20:15:10
  • Last modified 21.11.2024 07:24:06

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on commonly accessible documents including the menu macro can execute arbitrary Groovy, Python or Velocity code in XWik...