CVE-2025-29924
- EPSS 0.06%
- Veröffentlicht 19.03.2025 17:31:09
- Zuletzt bearbeitet 30.04.2025 15:58:41
XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, it's possible for an user to get access to private information through the REST API - but could also be through another API - when a sub wiki is using "Prevent un...
CVE-2025-24893
- EPSS 93.96%
- Veröffentlicht 20.02.2025 20:15:46
- Zuletzt bearbeitet 31.10.2025 13:17:09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availabi...
- EPSS 2.19%
- Veröffentlicht 14.01.2025 18:16:05
- Zuletzt bearbeitet 13.05.2025 13:34:05
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. NOTE: The Realtime WYSIWYG Editor extension was **experimental**, and thus **not recommended**, in the versions affected by this vulnerability. I...
CVE-2024-55877
- EPSS 27.48%
- Veröffentlicht 12.12.2024 20:15:21
- Zuletzt bearbeitet 30.04.2025 16:02:00
XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5.0, any user with an account can perform arbitrary remote code execution by adding instances of `XWiki.WikiMacroClass` to any page...
CVE-2024-55879
- EPSS 15.77%
- Veröffentlicht 12.12.2024 20:15:21
- Zuletzt bearbeitet 30.04.2025 16:01:22
XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with script rights can perform arbitrary remote code execution by adding instances of `XWiki.ConfigurableClass` to any page. This compr...
CVE-2024-55876
- EPSS 0.39%
- Veröffentlicht 12.12.2024 19:15:14
- Zuletzt bearbeitet 30.04.2025 16:02:40
XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0, any user with an account on the main wiki could run scheduling operations on subwikis. To reproduce, as a user on the main wiki w...
CVE-2024-55663
- EPSS 1.41%
- Veröffentlicht 12.12.2024 19:15:13
- Zuletzt bearbeitet 10.01.2025 18:02:02
XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 13.10.5 and 14.3-rc-1, in `getdocument.vm`; the ordering of the returned documents is defined from an unsanitized request parameter (request.sort) an...
CVE-2024-55662
- EPSS 9.82%
- Veröffentlicht 12.12.2024 18:15:27
- Zuletzt bearbeitet 30.04.2025 16:03:21
XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is installed, any user can execute any code requiring `programming` rights ...
CVE-2024-46979
- EPSS 0.38%
- Veröffentlicht 18.09.2024 18:15:07
- Zuletzt bearbeitet 07.02.2025 15:39:50
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to get access to notification filters of any user by using a URL such as `<hostname>xwiki/bin/get/XWiki/Notifications/Code/Notifica...
CVE-2024-46978
- EPSS 0.84%
- Veröffentlicht 18.09.2024 18:15:06
- Zuletzt bearbeitet 07.02.2025 15:48:36
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible for any user knowing the ID of a notification filter preference of another user, to enable/disable it or even delete it. The impact...