Xwiki

Xwiki

244 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.32%
  • Veröffentlicht 23.03.2021 23:15:13
  • Zuletzt bearbeitet 21.11.2024 05:48:14

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of XWiki Platform (and only those with the Ratings API installed), the Rating Script Service expose an API to perform SQL re...

  • EPSS 0.44%
  • Veröffentlicht 12.03.2021 18:15:12
  • Zuletzt bearbeitet 21.11.2024 05:48:14

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of XWiki Platform, the `{{wikimacrocontent}}` executes the content with the rights of the wiki macro author instead of the c...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 20.01.2021 04:15:13
  • Zuletzt bearbeitet 21.11.2024 06:20:58

XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.

  • EPSS 0.1%
  • Veröffentlicht 31.12.2020 01:15:12
  • Zuletzt bearbeitet 21.11.2024 05:01:41

XWiki Platform before 12.8 mishandles escaping in the property displayer.

Exploit
  • EPSS 2.7%
  • Veröffentlicht 16.10.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:05:11

In XWiki before version 12.5 and 11.10.6, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet context which contains tools allowing to instantiate arbitrary Java objects and invoke methods that m...

  • EPSS 0.73%
  • Veröffentlicht 10.09.2020 20:15:11
  • Zuletzt bearbeitet 21.11.2024 05:04:59

In XWiki before versions 11.10.5 or 12.2.1, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet context which contains tools allowing to instantiate arbitrary Java objects and invoke methods that...

Exploit
  • EPSS 1.75%
  • Veröffentlicht 12.05.2020 21:15:11
  • Zuletzt bearbeitet 21.11.2024 04:56:41

In XWiki Platform 7.2 through 11.10.2, registered users without scripting/programming permissions are able to execute python/groovy scripts while editing personal dashboards. This has been fixed 11.3.7 , 11.10.3 and 12.0.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 28.09.2018 00:29:01
  • Zuletzt bearbeitet 21.11.2024 03:52:26

The Image Import function in XWiki through 10.7 has XSS.

  • EPSS 0.12%
  • Veröffentlicht 30.12.2010 21:00:06
  • Zuletzt bearbeitet 11.04.2025 00:51:21

SQL injection vulnerability in XWiki Enterprise before 2.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • EPSS 0.07%
  • Veröffentlicht 30.12.2010 21:00:06
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in XWiki Enterprise before 2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.