VYPR

XWiki Platform Old Core

by Cryptpad

CVEs (1)

  • CVE-2026-34151higJul 7, 2026
    risk 0.45cvss epss

    ### Impact With Jetty 12+ a user can craft a URL to access any resource the Jetty instance is allowed to access. For example `http://[host]/xwiki/bin/skin/..%252f/..%252f..%252f..%252f..%252f..%252f..%252f..%252fetc/passwd` allows downloading the content of the /etc/passwd…