Xwiki

Xwiki

244 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 6.9%
  • Veröffentlicht 10.04.2024 21:15:07
  • Zuletzt bearbeitet 09.01.2025 18:54:53

XWiki Platform is a generic wiki platform. Starting in version 13.9-rc-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, when the realtime editor is installed in XWiki, it allows arbitrary remote code execution with the interaction of an admin...

Exploit
  • EPSS 13.75%
  • Veröffentlicht 10.04.2024 21:15:07
  • Zuletzt bearbeitet 09.01.2025 18:50:19

XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of escaping tool that is used in XWiki doesn't escape `{`, which, when used in certain places, allows XWiki ...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 10.04.2024 21:15:06
  • Zuletzt bearbeitet 23.01.2025 15:51:52

XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, it is possible to schedule/trigger/unschedule existing jobs by having an admin visit the Job Scheduler page through a predictabl...

Exploit
  • EPSS 7.9%
  • Veröffentlicht 10.04.2024 21:15:06
  • Zuletzt bearbeitet 21.01.2025 15:43:52

XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, by creating a document with a special crafted documented reference and an `XWiki.SchedulerJobClass` XObject, it is possible to e...

Exploit
  • EPSS 24.14%
  • Veröffentlicht 10.04.2024 20:15:08
  • Zuletzt bearbeitet 21.01.2025 16:26:42

XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, remote code execution is possible via PDF export templates. This vulnerability has been patched in XWiki 14.10.20, 15.5.4 and ...

Exploit
  • EPSS 94.27%
  • Veröffentlicht 10.04.2024 20:15:08
  • Zuletzt bearbeitet 25.09.2025 17:15:36

XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's database search allows remote code execution through the search text. This allows remote code execution for ...

Exploit
  • EPSS 23.3%
  • Veröffentlicht 10.04.2024 20:15:08
  • Zuletzt bearbeitet 21.01.2025 16:22:36

XWiki Platform is a generic wiki platform. In multilingual wikis, translations can be edited by any user who has edit right, circumventing the rights that are normally required for authoring translations (script right for user-scope translations, wik...

Exploit
  • EPSS 60.06%
  • Veröffentlicht 10.04.2024 20:15:08
  • Zuletzt bearbeitet 21.01.2025 16:20:37

XWiki Platform is a generic wiki platform. Starting in version 7.2-rc-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, by creating a document with a specially crafted title, it is possible to trigger remote code execution in the (Solr-based) ...

Exploit
  • EPSS 35.31%
  • Veröffentlicht 10.04.2024 20:15:07
  • Zuletzt bearbeitet 09.01.2025 16:49:22

XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.20, 15.5.4, and 15.9-rc-1, any user with edit right on any page can execute any code on the server by adding an object of type `XWiki.SearchSuggestSou...

  • EPSS 0.2%
  • Veröffentlicht 10.04.2024 19:15:49
  • Zuletzt bearbeitet 09.01.2025 16:41:19

XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.19, 15.5.4, and 15.9-rc-1, it is possible to access the hash of a password by using the diff feature of the history whenever the object storing the pa...