VYPR

Maven package

org.xwiki.platform/xwiki-platform-oldcore

pkg:maven/org.xwiki.platform/xwiki-platform-oldcore

Vulnerabilities (45)

  • CVE-2021-43841Feb 4, 2022
    affected < 12.10.6fixed 12.10.6

    XWiki is a generic wiki platform offering runtime services for applications built on top of it. When using default XWiki configuration, it's possible for an attacker to upload an SVG containing a script executed when executing the download action on the file. This problem has bee

  • CVE-2021-29459Apr 20, 2021
    affected < 12.6.3fixed 12.6.3

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible to persistently inject scripts in XWiki versions prior to 12.6.3 and 12.8. Unregistred users can fill simple text fields. Registered users can fill in their per

  • CVE-2020-15252Oct 16, 2020
    affected < 11.10.6fixed 11.10.6

    In XWiki before version 12.5 and 11.10.6, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet context which contains tools allowing to instantiate arbitrary Java objects and invoke methods that may lead to arbitrary code exec

  • CVE-2020-15171Sep 10, 2020
    affected < 11.10.5fixed 11.10.5

    In XWiki before versions 11.10.5 or 12.2.1, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet context which contains tools allowing to instantiate arbitrary Java objects and invoke methods that may lead to arbitrary code ex

  • CVE-2006-7223Sep 14, 2007
    affected >= 0.9.543, < 1.0B1fixed 1.0B1

    PreviewAction in XWiki 0.9.543 through 0.9.1252 does not set the Author field to the identity of the user who last modified a document, which allows remote authenticated users without programming rights to execute arbitrary code by selecting a document whose author has programmin

Page 3 of 3