CVE-2022-41937
- EPSS 9.73%
- Veröffentlicht 22.11.2022 01:15:36
- Zuletzt bearbeitet 21.11.2024 07:24:06
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application allows anyone with view access to modify any page of the wiki by importing a crafted XAR package. The problem has been patched in...
CVE-2022-41936
- EPSS 0.28%
- Veröffentlicht 22.11.2022 01:15:34
- Zuletzt bearbeitet 21.11.2024 07:24:06
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The `modifications` rest endpoint does not filter out entries according to the user's rights. Therefore, information hidden from unauthorized use...
CVE-2022-36097
- EPSS 44.19%
- Veröffentlicht 08.09.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:12:22
XWiki Platform Attachment UI provides a macro to easily upload and select attachments for XWiki Platform, a generic wiki platform. Starting with version 14.0-rc-1 and prior to 14.4-rc-1, it's possible to store JavaScript in an attachment name, which ...
- EPSS 43.65%
- Veröffentlicht 08.09.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:12:23
XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki platform. Starting in version 12.5-rc-1 and prior to versions 13.10.6 and 14.4, it's possible to store Javascript or groovy scripts...
CVE-2022-36099
- EPSS 21.71%
- Veröffentlicht 08.09.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:12:23
XWiki Platform Wiki UI Main Wiki is software for managing subwikis on XWiki Platform, a generic wiki platform. Starting with version 5.3-milestone-2 and prior to versions 13.10.6 and 14.4, it's possible to inject arbitrary wiki syntax including Groov...
CVE-2022-36100
- EPSS 8.28%
- Veröffentlicht 08.09.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 07:12:23
XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Starting with version 1.7 in XWiki Platform Applications Tag and prior to 13.10.6 and 14.4 in XWiki Platform Tag UI, the tags document ...
CVE-2022-36095
- EPSS 0.11%
- Veröffentlicht 08.09.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 07:12:22
XWiki Platform is a generic wiki platform. Prior to versions 13.10.5 and 14.3, it is possible to perform a Cross-Site Request Forgery (CSRF) attack for adding or removing tags on XWiki pages. The problem has been patched in XWiki 13.10.5 and 14.3. As...
- EPSS 54.51%
- Veröffentlicht 08.09.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 07:12:22
The XWiki Platform Index UI is an Index of all pages, attachments, orphans and deleted pages and attachments for XWiki Platform, a generic wiki platform. Prior to versions 13.10.6 and 14.3, it's possible to store JavaScript which will be executed by ...
- EPSS 49.21%
- Veröffentlicht 08.09.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 07:12:22
XWiki Platform Web Parent POM contains Web resources for the XWiki platform, a generic wiki platform. Starting with version 1.0 and prior to versions 13.10.6 and 14.30-rc-1, it's possible to store JavaScript which will be executed by anyone viewing t...
CVE-2022-36092
- EPSS 0.29%
- Veröffentlicht 08.09.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 07:12:22
XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 14.2 and 13.10.4, all rights checks that would normally prevent a user from viewing a document on a wiki can be bypassed using the login action a...