CVE-2023-50720
- EPSS 59.12%
- Veröffentlicht 15.12.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:37:12
XWiki Platform is a generic wiki platform. Prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the email addresses of users even when obfuscation of email addresses is enabled. To demonstrate the vulnerability,...
CVE-2023-50721
- EPSS 78.81%
- Veröffentlicht 15.12.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:37:12
XWiki Platform is a generic wiki platform. Starting in 4.5-rc-1 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the search administration interface doesn't properly escape the id and label of search user interface extensions, allowing the inje...
CVE-2023-50722
- EPSS 0.66%
- Veröffentlicht 15.12.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:37:12
XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, there is a reflected XSS or also direct remote code execution vulnerability in the code for displaying configurable admin sections. The ...
CVE-2023-48293
- EPSS 0.37%
- Veröffentlicht 20.11.2023 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:31:25
The XWiki Admin Tools Application provides tools to help the administration of XWiki. Prior to version 4.5.1, a cross-site request forgery vulnerability in the query on XWiki tool allows executing arbitrary database queries on the database of the XWi...
CVE-2023-48240
- EPSS 0.71%
- Veröffentlicht 20.11.2023 18:15:07
- Zuletzt bearbeitet 21.11.2024 08:31:17
XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents and not display a difference for an actually unchanged image. For this, XWiki requests all embedded images on the server side. Thes...
CVE-2023-48241
- EPSS 72.82%
- Veröffentlicht 20.11.2023 18:15:07
- Zuletzt bearbeitet 21.11.2024 08:31:17
XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, and 15.6RC1, the Solr-based search suggestion provider that also duplicates as generic JavaScript API for search results in XWiki e...
CVE-2023-46243
- EPSS 0.99%
- Veröffentlicht 07.11.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 08:28:09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a user to execute any content with the right of an existing document's content author, provided the user h...
CVE-2023-46242
- EPSS 0.38%
- Veröffentlicht 07.11.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 08:28:09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to execute a content with the right of any user via a crafted URL. A user must have `programming` privileges i...
CVE-2023-46244
- EPSS 0.79%
- Veröffentlicht 07.11.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 08:28:09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a user to write a script in which any velocity content is executed with the right of any other document co...
CVE-2023-38509
- EPSS 0.66%
- Veröffentlicht 07.11.2023 04:17:20
- Zuletzt bearbeitet 21.11.2024 08:13:43
XWiki Platform is a generic wiki platform. In org.xwiki.platform:xwiki-platform-livetable-ui starting with version 3.5-milestone-1 and prior to versions 14.10.9 and 15.3-rc-1, the mail obfuscation configuration was not fully taken into account and is...