CVE-2023-48240
- EPSS 1.58%
- Veröffentlicht 20.11.2023 18:15:07
- Zuletzt bearbeitet 21.11.2024 08:31:17
XWiki Platform is a generic wiki platform. The rendered diff in XWiki embeds images to be able to compare the contents and not display a difference for an actually unchanged image. For this, XWiki requests all embedded images on the server side. Thes...
CVE-2023-48241
- EPSS 69.19%
- Veröffentlicht 20.11.2023 18:15:07
- Zuletzt bearbeitet 21.11.2024 08:31:17
XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, and 15.6RC1, the Solr-based search suggestion provider that also duplicates as generic JavaScript API for search results in XWiki e...
CVE-2023-46243
- EPSS 7.48%
- Veröffentlicht 07.11.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 08:28:09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a user to execute any content with the right of an existing document's content author, provided the user h...
CVE-2023-46242
- EPSS 3.25%
- Veröffentlicht 07.11.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 08:28:09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to execute a content with the right of any user via a crafted URL. A user must have `programming` privileges i...
CVE-2023-46244
- EPSS 1.42%
- Veröffentlicht 07.11.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 08:28:09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a user to write a script in which any velocity content is executed with the right of any other document co...
CVE-2023-38509
- EPSS 0.36%
- Veröffentlicht 07.11.2023 04:17:20
- Zuletzt bearbeitet 21.11.2024 08:13:43
XWiki Platform is a generic wiki platform. In org.xwiki.platform:xwiki-platform-livetable-ui starting with version 3.5-milestone-1 and prior to versions 14.10.9 and 15.3-rc-1, the mail obfuscation configuration was not fully taken into account and is...
CVE-2023-46731
- EPSS 57.47%
- Veröffentlicht 06.11.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:29:10
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki doesn't properly escape the section URL parameter that is used in the code for displaying administration sections. This allows any user wit...
CVE-2023-46732
- EPSS 55.56%
- Veröffentlicht 06.11.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:29:11
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to reflected cross-site scripting (RXSS) via the `rev` parameter that is used in the content of the content menu without esca...
CVE-2023-45137
- EPSS 1.7%
- Veröffentlicht 25.10.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 08:26:25
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. `org.xwiki.platform:xwiki-platform-web` starting in version 3.1-milestone-2 and prior to version 13.4-rc-1, as well as `org.xwiki.platform:xwiki-...
CVE-2023-45136
- EPSS 74.96%
- Veröffentlicht 25.10.2023 20:15:12
- Zuletzt bearbeitet 21.11.2024 08:26:25
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When document names are validated according to a name strategy (disabled by default), XWiki starting in version 12.0-rc-1 and prior to versions 1...