- EPSS 1.38%
- Veröffentlicht 30.04.2025 14:55:01
- Zuletzt bearbeitet 13.05.2025 14:55:03
XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.8 and from 16.0.0-rc-1 to before 16.2.0, the required rights analysis doesn't consider TextAreas with default content type. When editing a page, XWiki warns since v...
CVE-2025-32972
- EPSS 0.12%
- Veröffentlicht 30.04.2025 14:54:58
- Zuletzt bearbeitet 13.05.2025 15:05:07
XWiki is a generic wiki platform. In versions starting from 6.1-milestone-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.8.0-rc-1, the script API of the LESS compiler in XWiki is incorrectly checking for ri...
CVE-2025-32971
- EPSS 0.09%
- Veröffentlicht 30.04.2025 14:54:55
- Zuletzt bearbeitet 13.05.2025 15:06:38
XWiki is a generic wiki platform. In versions starting from 4.5.1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0-rc-1, the Solr script service doesn't take dropped programming rights into account. The Sol...
CVE-2025-32970
- EPSS 0.17%
- Veröffentlicht 30.04.2025 14:54:52
- Zuletzt bearbeitet 13.05.2025 15:13:38
XWiki is a generic wiki platform. In versions starting from 13.5-rc-1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0, an open redirect vulnerability in the HTML conversion request filter allows attackers ...
CVE-2025-32969
- EPSS 26.18%
- Veröffentlicht 23.04.2025 15:33:03
- Zuletzt bearbeitet 30.04.2025 15:50:37
XWiki is a generic wiki platform. In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possible for a remote unauthenticated user to escape from the HQL execution context and perform a blind SQL injection to execute arbitra...
CVE-2025-32968
- EPSS 0.91%
- Veröffentlicht 23.04.2025 15:27:27
- Zuletzt bearbeitet 30.04.2025 16:09:17
XWiki is a generic wiki platform. In versions starting from 1.6-milestone-1 to before 15.10.16, 16.4.6, and 16.10.1, it is possible for a user with SCRIPT right to escape from the HQL execution context and perform a blind SQL injection to execute arb...
CVE-2025-32783
- EPSS 0.13%
- Veröffentlicht 16.04.2025 21:38:06
- Zuletzt bearbeitet 30.04.2025 15:56:09
XWiki Platform is a generic wiki platform. A vulnerability in versions from 5.0 to 16.7.1 affects users with Message Stream enabled and a wiki configured as closed from selecting "Prevent unregistered users to view pages" in the Administrations Right...
CVE-2025-29926
- EPSS 1.5%
- Veröffentlicht 19.03.2025 17:40:44
- Zuletzt bearbeitet 13.05.2025 13:34:02
XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager REST API to create a new wiki, where the user could become an administrator and so performs other attacks on the farm. Note that t...
CVE-2025-29925
- EPSS 0.45%
- Veröffentlicht 19.03.2025 17:36:28
- Zuletzt bearbeitet 30.04.2025 15:57:32
XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, protected pages are listed when requesting the REST endpoints /rest/wikis/[wikiName]/pages even if the user doesn't have view rights on them. It's particularly tr...
CVE-2025-29924
- EPSS 0.06%
- Veröffentlicht 19.03.2025 17:31:09
- Zuletzt bearbeitet 30.04.2025 15:58:41
XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, it's possible for an user to get access to private information through the REST API - but could also be through another API - when a sub wiki is using "Prevent un...