Xwiki

Xwiki

248 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.34%
  • Veröffentlicht 24.06.2024 17:15:10
  • Zuletzt bearbeitet 21.11.2024 09:25:28

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The content of a document included using `{{include reference="targetdocument"/}}` is executed with the right of the includer and not with the ri...

Exploit
  • EPSS 0.69%
  • Veröffentlicht 20.06.2024 23:15:52
  • Zuletzt bearbeitet 05.02.2025 16:01:02

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an admin disables a user account, the user's profile is executed with the admin's rights. This allows a user to place malicious code in the ...

Exploit
  • EPSS 73.93%
  • Veröffentlicht 10.04.2024 22:15:07
  • Zuletzt bearbeitet 09.01.2025 19:02:51

XWiki Platform is a generic wiki platform. Prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, parameters of UI extensions are always interpreted as Velocity code and executed with programming rights. Any user with edit right on any document like the ...

Exploit
  • EPSS 1.45%
  • Veröffentlicht 10.04.2024 21:15:07
  • Zuletzt bearbeitet 21.01.2025 15:35:42

XWiki Platform is a generic wiki platform. Starting in version 6.4-milestone-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, any user who can edit any page like their profile can create a custom skin with a template override that is executed...

Exploit
  • EPSS 0.7%
  • Veröffentlicht 10.04.2024 21:15:07
  • Zuletzt bearbeitet 09.01.2025 18:54:53

XWiki Platform is a generic wiki platform. Starting in version 13.9-rc-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, when the realtime editor is installed in XWiki, it allows arbitrary remote code execution with the interaction of an admin...

Exploit
  • EPSS 2.1%
  • Veröffentlicht 10.04.2024 21:15:07
  • Zuletzt bearbeitet 09.01.2025 18:50:19

XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of escaping tool that is used in XWiki doesn't escape `{`, which, when used in certain places, allows XWiki ...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 10.04.2024 21:15:06
  • Zuletzt bearbeitet 23.01.2025 15:51:52

XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, it is possible to schedule/trigger/unschedule existing jobs by having an admin visit the Job Scheduler page through a predictabl...

Exploit
  • EPSS 0.55%
  • Veröffentlicht 10.04.2024 21:15:06
  • Zuletzt bearbeitet 21.01.2025 15:43:52

XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, by creating a document with a special crafted documented reference and an `XWiki.SchedulerJobClass` XObject, it is possible to e...

Exploit
  • EPSS 1.45%
  • Veröffentlicht 10.04.2024 20:15:08
  • Zuletzt bearbeitet 21.01.2025 16:26:42

XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, remote code execution is possible via PDF export templates. This vulnerability has been patched in XWiki 14.10.20, 15.5.4 and ...

Exploit
  • EPSS 34.52%
  • Veröffentlicht 10.04.2024 20:15:08
  • Zuletzt bearbeitet 25.09.2025 17:15:36

XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's database search allows remote code execution through the search text. This allows remote code execution for ...