Xwiki

Xwiki

244 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.38%
  • Veröffentlicht 30.04.2025 14:55:01
  • Zuletzt bearbeitet 13.05.2025 14:55:03

XWiki is a generic wiki platform. In versions starting from 15.9-rc-1 to before 15.10.8 and from 16.0.0-rc-1 to before 16.2.0, the required rights analysis doesn't consider TextAreas with default content type. When editing a page, XWiki warns since v...

  • EPSS 0.12%
  • Veröffentlicht 30.04.2025 14:54:58
  • Zuletzt bearbeitet 13.05.2025 15:05:07

XWiki is a generic wiki platform. In versions starting from 6.1-milestone-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.8.0-rc-1, the script API of the LESS compiler in XWiki is incorrectly checking for ri...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 30.04.2025 14:54:55
  • Zuletzt bearbeitet 13.05.2025 15:06:38

XWiki is a generic wiki platform. In versions starting from 4.5.1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0-rc-1, the Solr script service doesn't take dropped programming rights into account. The Sol...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 30.04.2025 14:54:52
  • Zuletzt bearbeitet 13.05.2025 15:13:38

XWiki is a generic wiki platform. In versions starting from 13.5-rc-1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0, an open redirect vulnerability in the HTML conversion request filter allows attackers ...

Exploit
  • EPSS 26.18%
  • Veröffentlicht 23.04.2025 15:33:03
  • Zuletzt bearbeitet 30.04.2025 15:50:37

XWiki is a generic wiki platform. In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possible for a remote unauthenticated user to escape from the HQL execution context and perform a blind SQL injection to execute arbitra...

Exploit
  • EPSS 0.91%
  • Veröffentlicht 23.04.2025 15:27:27
  • Zuletzt bearbeitet 30.04.2025 16:09:17

XWiki is a generic wiki platform. In versions starting from 1.6-milestone-1 to before 15.10.16, 16.4.6, and 16.10.1, it is possible for a user with SCRIPT right to escape from the HQL execution context and perform a blind SQL injection to execute arb...

Exploit
  • EPSS 0.13%
  • Veröffentlicht 16.04.2025 21:38:06
  • Zuletzt bearbeitet 30.04.2025 15:56:09

XWiki Platform is a generic wiki platform. A vulnerability in versions from 5.0 to 16.7.1 affects users with Message Stream enabled and a wiki configured as closed from selecting "Prevent unregistered users to view pages" in the Administrations Right...

Exploit
  • EPSS 1.5%
  • Veröffentlicht 19.03.2025 17:40:44
  • Zuletzt bearbeitet 13.05.2025 13:34:02

XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager REST API to create a new wiki, where the user could become an administrator and so performs other attacks on the farm. Note that t...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 19.03.2025 17:36:28
  • Zuletzt bearbeitet 30.04.2025 15:57:32

XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, protected pages are listed when requesting the REST endpoints /rest/wikis/[wikiName]/pages even if the user doesn't have view rights on them. It's particularly tr...

  • EPSS 0.06%
  • Veröffentlicht 19.03.2025 17:31:09
  • Zuletzt bearbeitet 30.04.2025 15:58:41

XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, it's possible for an user to get access to private information through the REST API - but could also be through another API - when a sub wiki is using "Prevent un...