Xwiki

Xwiki

245 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 10.04.2024 19:15:49
  • Zuletzt bearbeitet 09.01.2025 16:41:19

XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.19, 15.5.4, and 15.9-rc-1, it is possible to access the hash of a password by using the diff feature of the history whenever the object storing the pa...

  • EPSS 0.34%
  • Veröffentlicht 09.01.2024 00:15:44
  • Zuletzt bearbeitet 21.11.2024 08:54:47

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The rollback action is missing a right protection, a user can rollback to a previous version of the page to gain rights they don't have anymore. ...

  • EPSS 0.5%
  • Veröffentlicht 09.01.2024 00:15:44
  • Zuletzt bearbeitet 21.11.2024 08:54:48

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to attach a file to a page can post a malformed TAR file by manipulating file modification times headers, which when parsed by Tika, ...

Exploit
  • EPSS 92.54%
  • Veröffentlicht 08.01.2024 16:15:46
  • Zuletzt bearbeitet 21.11.2024 08:54:48

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code execution (RCE) attack through its user registration feature. This issue allows an attacker to execute arbit...

Exploit
  • EPSS 1.36%
  • Veröffentlicht 21.12.2023 20:15:07
  • Zuletzt bearbeitet 21.11.2024 08:37:14

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute a Velocity script without script right through the document tree. This has been patched in XWiki 14.10.7 and 15.2RC1.

  • EPSS 5.39%
  • Veröffentlicht 15.12.2023 19:15:10
  • Zuletzt bearbeitet 21.11.2024 08:37:12

XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, anyone who can edit an arbitrary wiki page in an XWiki installation can gain programming right through several cases of missing escaping...

  • EPSS 51.13%
  • Veröffentlicht 15.12.2023 19:15:09
  • Zuletzt bearbeitet 21.11.2024 08:37:12

XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password hashes of all users to anyone with view right on the respective user p...

  • EPSS 49.72%
  • Veröffentlicht 15.12.2023 19:15:09
  • Zuletzt bearbeitet 21.11.2024 08:37:12

XWiki Platform is a generic wiki platform. Prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the email addresses of users even when obfuscation of email addresses is enabled. To demonstrate the vulnerability,...

  • EPSS 43.25%
  • Veröffentlicht 15.12.2023 19:15:09
  • Zuletzt bearbeitet 21.11.2024 08:37:12

XWiki Platform is a generic wiki platform. Starting in 4.5-rc-1 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the search administration interface doesn't properly escape the id and label of search user interface extensions, allowing the inje...

  • EPSS 3.26%
  • Veröffentlicht 15.12.2023 19:15:09
  • Zuletzt bearbeitet 21.11.2024 08:37:12

XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, there is a reflected XSS or also direct remote code execution vulnerability in the code for displaying configurable admin sections. The ...