Xwiki

Xwiki

248 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 23.11.2022 19:15:12
  • Zuletzt bearbeitet 21.11.2024 07:24:05

XWiki Platform is vulnerable to Cross-Site Request Forgery (CSRF) that may allow attackers to delete or rename tags without needing any confirmation. The problem has been patched in XWiki 13.10.7, 14.4.1 and 14.5RC1. Workarounds: It's possible to pat...

Exploit
  • EPSS 0.98%
  • Veröffentlicht 23.11.2022 19:15:12
  • Zuletzt bearbeitet 21.11.2024 07:24:05

XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in AttachmentSelector.xml. The issue can also be reproduced by inserting the dangerous payload in the `height` or `alt` macro properti...

Exploit
  • EPSS 0.71%
  • Veröffentlicht 23.11.2022 19:15:12
  • Zuletzt bearbeitet 21.11.2024 07:24:05

org.xwiki.platform:xwiki-platform-oldcore is missing authorization in User#setDisabledStatus, which may allow an incorrectly authorized user with only Script rights to enable or disable a user. This operation is meant to only be available for users w...

Exploit
  • EPSS 0.82%
  • Veröffentlicht 23.11.2022 19:15:12
  • Zuletzt bearbeitet 21.11.2024 07:24:05

org.xwiki.platform:xwiki-platform-user-profile-ui is missing authorization to enable or disable users. Any user (logged in or not) with access to the page XWiki.XWikiUserProfileSheet can enable or disable any user profile. This might allow to a disab...

  • EPSS 0.73%
  • Veröffentlicht 22.11.2022 01:15:36
  • Zuletzt bearbeitet 21.11.2024 07:24:06

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application allows anyone with view access to modify any page of the wiki by importing a crafted XAR package. The problem has been patched in...

  • EPSS 0.72%
  • Veröffentlicht 22.11.2022 01:15:34
  • Zuletzt bearbeitet 21.11.2024 07:24:06

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The `modifications` rest endpoint does not filter out entries according to the user's rights. Therefore, information hidden from unauthorized use...

Exploit
  • EPSS 57.39%
  • Veröffentlicht 08.09.2022 21:15:08
  • Zuletzt bearbeitet 21.11.2024 07:12:22

XWiki Platform Attachment UI provides a macro to easily upload and select attachments for XWiki Platform, a generic wiki platform. Starting with version 14.0-rc-1 and prior to 14.4-rc-1, it's possible to store JavaScript in an attachment name, which ...

Exploit
  • EPSS 71.04%
  • Veröffentlicht 08.09.2022 21:15:08
  • Zuletzt bearbeitet 21.11.2024 07:12:23

XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki platform. Starting in version 12.5-rc-1 and prior to versions 13.10.6 and 14.4, it's possible to store Javascript or groovy scripts...

Exploit
  • EPSS 75.89%
  • Veröffentlicht 08.09.2022 21:15:08
  • Zuletzt bearbeitet 21.11.2024 07:12:23

XWiki Platform Wiki UI Main Wiki is software for managing subwikis on XWiki Platform, a generic wiki platform. Starting with version 5.3-milestone-2 and prior to versions 13.10.6 and 14.4, it's possible to inject arbitrary wiki syntax including Groov...

Exploit
  • EPSS 73.61%
  • Veröffentlicht 08.09.2022 21:15:08
  • Zuletzt bearbeitet 21.11.2024 07:12:23

XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Starting with version 1.7 in XWiki Platform Applications Tag and prior to 13.10.6 and 14.4 in XWiki Platform Tag UI, the tags document ...