Maven package
org.xwiki.platform/xwiki-web-standard
pkg:maven/org.xwiki.platform/xwiki-web-standard
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-45134 | — | >= 2.4-milestone-2, < 3.1-milestone-1 | 3.1-milestone-1 | Oct 25, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. `org.xwiki.platform:xwiki-platform-web` starting in version 3.1-milestone-1 and prior to 13.4-rc-1, `org.xwiki.platform:xwiki-platform-web-templates` prior to versions 14.10.2 | ||
| CVE-2023-29207 | — | >= 1.9-milestone-2, < 13.10.10 | 13.10.10 | Apr 15, 2023 | XWiki Commons are technical libraries common to several other top level XWiki projects. The Livetable Macro wasn't properly sanitizing column names, thus allowing the insertion of raw HTML code including JavaScript. This vulnerability was also exploitable via the Documents Macro |
- CVE-2023-45134Oct 25, 2023affected >= 2.4-milestone-2, < 3.1-milestone-1fixed 3.1-milestone-1
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. `org.xwiki.platform:xwiki-platform-web` starting in version 3.1-milestone-1 and prior to 13.4-rc-1, `org.xwiki.platform:xwiki-platform-web-templates` prior to versions 14.10.2
- CVE-2023-29207Apr 15, 2023affected >= 1.9-milestone-2, < 13.10.10fixed 13.10.10
XWiki Commons are technical libraries common to several other top level XWiki projects. The Livetable Macro wasn't properly sanitizing column names, thus allowing the insertion of raw HTML code including JavaScript. This vulnerability was also exploitable via the Documents Macro