CVE-2024-55663
- EPSS 1.57%
- Published 12.12.2024 19:15:13
- Last modified 10.01.2025 18:02:02
XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 13.10.5 and 14.3-rc-1, in `getdocument.vm`; the ordering of the returned documents is defined from an unsanitized request parameter (request.sort) an...
CVE-2024-55662
- EPSS 44.08%
- Published 12.12.2024 18:15:27
- Last modified 30.04.2025 16:03:21
XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is installed, any user can execute any code requiring `programming` rights ...
CVE-2024-46979
- EPSS 0.03%
- Published 18.09.2024 18:15:07
- Last modified 07.02.2025 15:39:50
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to get access to notification filters of any user by using a URL such as `<hostname>xwiki/bin/get/XWiki/Notifications/Code/Notifica...
CVE-2024-46978
- EPSS 0.18%
- Published 18.09.2024 18:15:06
- Last modified 07.02.2025 15:48:36
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible for any user knowing the ID of a notification filter preference of another user, to enable/disable it or even delete it. The impact...
CVE-2024-45591
- EPSS 48.84%
- Published 10.09.2024 16:15:21
- Last modified 20.09.2024 19:55:54
XWiki Platform is a generic wiki platform. The REST API exposes the history of any page in XWiki of which the attacker knows the name. The exposed information includes for each modification of the page the time of the modification, the version number...
CVE-2024-43400
- EPSS 4.27%
- Published 19.08.2024 17:15:09
- Last modified 20.08.2024 16:10:29
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible for a user without Script or Programming rights to craft a URL pointing to a page with arbitrary JavaScript. This requires social ...
- EPSS 1.41%
- Published 19.08.2024 17:15:09
- Last modified 20.08.2024 16:09:23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor. ...
CVE-2024-41947
- EPSS 7.63%
- Published 31.07.2024 16:15:04
- Last modified 06.09.2024 20:46:01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a conflict when another user with more rights is currently editing a page, it is possible to execute JavaScript snippets on the side ...
CVE-2024-37898
- EPSS 0.17%
- Published 31.07.2024 16:15:03
- Last modified 06.09.2024 21:16:55
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When a user has view but not edit right on a page in XWiki, that user can delete the page and replace it by a page with new content without havin...
CVE-2024-37900
- EPSS 6.72%
- Published 31.07.2024 16:15:03
- Last modified 10.01.2025 16:54:03
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When uploading an attachment with a malicious filename, malicious JavaScript code could be executed. This requires a social engineering attack to...