CVE-2025-49584
- EPSS 0.04%
- Veröffentlicht 13.06.2025 17:21:33
- Zuletzt bearbeitet 03.09.2025 17:48:29
XWiki is a generic wiki platform. In XWiki Platform versions 10.9 through 16.4.6, 16.5.0-rc-1 through 16.10.2, and 17.0.0-rc-1, the title of every single page whose reference is known can be accessed through the REST API as long as an XClass with a p...
CVE-2025-49583
- EPSS 0.02%
- Veröffentlicht 13.06.2025 17:15:23
- Zuletzt bearbeitet 03.09.2025 17:50:20
XWiki is a generic wiki platform. When a user without script right creates a document with an `XWiki.Notifications.Code.NotificationEmailRendererClass` object, and later an admin edits and saves that document, the email templates in this object will ...
- EPSS 0.61%
- Veröffentlicht 13.06.2025 16:41:45
- Zuletzt bearbeitet 03.09.2025 17:50:47
XWiki is a generic wiki platform. When editing content that contains "dangerous" macros like malicious script macros that were authored by a user with fewer rights, XWiki warns about the execution of these macros since XWiki 15.9RC1. These required r...
CVE-2025-49581
- EPSS 1.58%
- Veröffentlicht 13.06.2025 16:09:22
- Zuletzt bearbeitet 03.09.2025 17:51:15
XWiki is a generic wiki platform. Any user with edit right on a page (could be the user's profile) can execute code (Groovy, Python, Velocity) with programming right by defining a wiki macro. This allows full access to the whole XWiki installation. T...
- EPSS 0.32%
- Veröffentlicht 13.06.2025 15:45:58
- Zuletzt bearbeitet 03.09.2025 17:52:44
XWiki is a generic wiki platform. From 8.2 and 7.4.5 until 17.1.0-rc-1, 16.10.4, and 16.4.7, pages can gain script or programming rights when they contain a link and the target of the link is renamed or moved. This might lead to execution of scripts ...
CVE-2024-56158
- EPSS 0.59%
- Veröffentlicht 12.06.2025 14:56:56
- Zuletzt bearbeitet 12.01.2026 15:16:01
XWiki is a generic wiki platform. It's possible to execute any SQL query in Oracle by using the function like DBMS_XMLGEN or DBMS_XMLQUERY. The XWiki query validator does not sanitize functions that would be used in a simple select and Hibernate allo...
CVE-2025-46554
- EPSS 0.09%
- Veröffentlicht 30.04.2025 18:27:53
- Zuletzt bearbeitet 03.09.2025 17:53:01
XWiki is a generic wiki platform. In versions starting from 1.8.1 to before 14.10.22, from 15.0-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.7.0, anyone can access the metadata of any attachment in the...
CVE-2025-46557
- EPSS 0.37%
- Veröffentlicht 30.04.2025 18:27:39
- Zuletzt bearbeitet 03.09.2025 17:52:56
XWiki is a generic wiki platform. In versions starting from 15.3-rc-1 to before 15.10.14, from 16.0.0-rc-1 to before 16.4.6, and from 16.5.0-rc-1 to before 16.10.0-rc-1, a user who can access pages located in the XWiki space (by default, anyone) can ...
- EPSS 3.03%
- Veröffentlicht 30.04.2025 18:27:30
- Zuletzt bearbeitet 26.08.2025 16:28:44
XWiki Contrib's Syntax Markdown allows importing Markdown content into wiki pages and creating wiki content in Markdown. In versions starting from 8.2 to before 8.9, the Markdown syntax is vulnerable to cross-site scripting (XSS) through HTML. In par...
- EPSS 2.24%
- Veröffentlicht 30.04.2025 14:55:04
- Zuletzt bearbeitet 13.05.2025 14:58:48
XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.8.0-rc-1, when a user with programming rights edits a document in XWiki that was last edite...