CVE-2025-54125
- EPSS 0.64%
- Veröffentlicht 05.08.2025 23:30:38
- Zuletzt bearbeitet 02.09.2025 19:24:04
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 1.1 through 16.4.6, 16.5.0-rc-1 through 16.10.4 and 17.0.0-rc-1 through 17.1....
CVE-2025-54124
- EPSS 0.03%
- Veröffentlicht 05.08.2025 23:28:07
- Zuletzt bearbeitet 02.09.2025 19:24:15
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 9.8-rc-1 through 16.4.6, 16.5.0-rc-1 through 16.10.4, and 17.0.0-rc-1 through...
CVE-2025-32430
- EPSS 0.09%
- Veröffentlicht 05.08.2025 23:27:07
- Zuletzt bearbeitet 02.09.2025 19:24:23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-3 through 16.4.7, 16.5.0-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, two templates contain reflected XSS vulne...
CVE-2025-54385
- EPSS 0.59%
- Veröffentlicht 26.07.2025 03:28:49
- Zuletzt bearbeitet 03.09.2025 17:42:29
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions between 17.0.0-rc1 to 17.2.2 and versions 16.10.5 and below, it's possible to execute any SQL query in Oracle by using the function l...
CVE-2025-32429
- EPSS 32.14%
- Veröffentlicht 24.07.2025 23:15:26
- Zuletzt bearbeitet 03.09.2025 17:43:28
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getde...
CVE-2025-53836
- EPSS 2.06%
- Veröffentlicht 14.07.2025 23:08:34
- Zuletzt bearbeitet 26.08.2025 17:52:16
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 4.2-milestone-1 and prior to versions 13.10.11, 14.4.7, and 14.10, the default ...
- EPSS 1.62%
- Veröffentlicht 14.07.2025 23:00:35
- Zuletzt bearbeitet 26.08.2025 17:52:40
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 5.4.5 and prior to version 14.10, the XHTML syntax depended on the `xdom+xml/cu...
- EPSS 0.23%
- Veröffentlicht 13.06.2025 17:51:48
- Zuletzt bearbeitet 03.09.2025 17:44:02
XWiki is an open-source wiki software platform. When a user without script right creates a document with an XWiki.Notifications.Code.NotificationDisplayerClass object, and later an admin edits and saves that document, the possibly malicious content o...
CVE-2025-49586
- EPSS 4.55%
- Veröffentlicht 13.06.2025 17:47:07
- Zuletzt bearbeitet 03.09.2025 17:47:10
XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes application (the default for all users XWiki) can obtain programming right/perform remote code execution by editing the application. Thi...
- EPSS 0.23%
- Veröffentlicht 13.06.2025 17:33:34
- Zuletzt bearbeitet 03.09.2025 17:47:36
XWiki is a generic wiki platform. In versions before 15.10.16, 16.0.0-rc-1 through 16.4.6, and 16.5.0-rc-1 through 16.10.1, when an attacker without script or programming right creates an XClass definition in XWiki (requires edit right), and that sam...