Medium severity5.4NVD Advisory· Published Jan 20, 2021· Updated Jun 17, 2026
CVE-2021-3137
CVE-2021-3137
Description
XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.xwiki.commons:xwiki-commonsMaven | < 12.10.3 | 12.10.3 |
Affected products
3- XWiki/XWikidescription
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/49437nvdExploitThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-43hg-g44q-474qghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-3137ghsaADVISORY
News mentions
0No linked articles in our index yet.