Xwiki

Xwiki

244 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung Medienbericht Exploit
  • EPSS 94.24%
  • Veröffentlicht 20.02.2025 20:15:46
  • Zuletzt bearbeitet 31.10.2025 13:17:09

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availabi...

  • EPSS 2.19%
  • Veröffentlicht 14.01.2025 18:16:05
  • Zuletzt bearbeitet 13.05.2025 13:34:05

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. NOTE: The Realtime WYSIWYG Editor extension was **experimental**, and thus **not recommended**, in the versions affected by this vulnerability. I...

Exploit
  • EPSS 27.48%
  • Veröffentlicht 12.12.2024 20:15:21
  • Zuletzt bearbeitet 30.04.2025 16:02:00

XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5.0, any user with an account can perform arbitrary remote code execution by adding instances of `XWiki.WikiMacroClass` to any page...

Exploit
  • EPSS 19.79%
  • Veröffentlicht 12.12.2024 20:15:21
  • Zuletzt bearbeitet 30.04.2025 16:01:22

XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with script rights can perform arbitrary remote code execution by adding instances of `XWiki.ConfigurableClass` to any page. This compr...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 12.12.2024 19:15:14
  • Zuletzt bearbeitet 30.04.2025 16:02:40

XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0, any user with an account on the main wiki could run scheduling operations on subwikis. To reproduce, as a user on the main wiki w...

  • EPSS 1.41%
  • Veröffentlicht 12.12.2024 19:15:13
  • Zuletzt bearbeitet 10.01.2025 18:02:02

XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 13.10.5 and 14.3-rc-1, in `getdocument.vm`; the ordering of the returned documents is defined from an unsanitized request parameter (request.sort) an...

Exploit
  • EPSS 9.82%
  • Veröffentlicht 12.12.2024 18:15:27
  • Zuletzt bearbeitet 30.04.2025 16:03:21

XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is installed, any user can execute any code requiring `programming` rights ...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 18.09.2024 18:15:07
  • Zuletzt bearbeitet 07.02.2025 15:39:50

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to get access to notification filters of any user by using a URL such as `<hostname>xwiki/bin/get/XWiki/Notifications/Code/Notifica...

Exploit
  • EPSS 0.88%
  • Veröffentlicht 18.09.2024 18:15:06
  • Zuletzt bearbeitet 07.02.2025 15:48:36

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible for any user knowing the ID of a notification filter preference of another user, to enable/disable it or even delete it. The impact...

Exploit
  • EPSS 85.23%
  • Veröffentlicht 10.09.2024 16:15:21
  • Zuletzt bearbeitet 20.09.2024 19:55:54

XWiki Platform is a generic wiki platform. The REST API exposes the history of any page in XWiki of which the attacker knows the name. The exposed information includes for each modification of the page the time of the modification, the version number...