VYPR

Maven package

org.xwiki.platform/xwiki-web-standard

pkg:maven/org.xwiki.platform/xwiki-web-standard

Vulnerabilities (2)

  • CVE-2023-45134Oct 25, 2023
    affected >= 2.4-milestone-2, < 3.1-milestone-1fixed 3.1-milestone-1

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. `org.xwiki.platform:xwiki-platform-web` starting in version 3.1-milestone-1 and prior to 13.4-rc-1, `org.xwiki.platform:xwiki-platform-web-templates` prior to versions 14.10.2

  • CVE-2023-29207Apr 15, 2023
    affected >= 1.9-milestone-2, < 13.10.10fixed 13.10.10

    XWiki Commons are technical libraries common to several other top level XWiki projects. The Livetable Macro wasn't properly sanitizing column names, thus allowing the insertion of raw HTML code including JavaScript. This vulnerability was also exploitable via the Documents Macro