VYPR

Xwiki

by Cryptpad

Source repositories

CVEs (251)

  • CVE-2023-29520MedApr 19, 2023
    risk 0.28cvss 4.3epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to break many translations coming from wiki pages by creating a corrupted document containing a translation object. This will lead to a broken page. The…

  • CVE-2023-29506MedApr 16, 2023
    risk 0.28cvss 5.4epss 0.02

    XWiki Commons are technical libraries common to several other top level XWiki projects. It was possible to inject some code using the URL of authenticated endpoints. This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10.

  • CVE-2023-26056MedMar 2, 2023
    risk 0.28cvss 5.4epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 3.0-milestone-1, it's possible to execute a script with the right of another user, provided the target user does not have programming right. The problem has been patched in XWiki 14.8-rc-1, 14.4.5, and 13.10.10.…

  • CVE-2022-41935MedNov 23, 2022
    risk 0.28cvss 5.3epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users without the right to view documents can deduce their existence by repeated Livetable queries. The issue has been patched in XWiki 14.6RC1, 13.10.8, and 14.4.3, the…

  • CVE-2022-41936MedNov 22, 2022
    risk 0.28cvss 5.3epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The `modifications` rest endpoint does not filter out entries according to the user's rights. Therefore, information hidden from unauthorized users are exposed though the…

  • CVE-2022-29161MedMay 6, 2022
    risk 0.28cvss 5.4epss 0.00

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypto API will generate X509 certificates signed by default using SHA1 with RSA, which is not considered safe anymore for use in certificate signatures, due to the…

  • CVE-2022-23619MedFeb 9, 2022
    risk 0.28cvss 5.3epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to guess if a user has an account on the wiki by using the "Forgot your password" form, even if the wiki is closed to guest users. This…

  • CVE-2022-23615MedFeb 9, 2022
    risk 0.28cvss 5.4epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can save a document with the right of the current user which allow accessing API requiring programming right if the current…

  • CVE-2021-43841MedFeb 4, 2022
    risk 0.28cvss 5.4epss 0.01

    XWiki is a generic wiki platform offering runtime services for applications built on top of it. When using default XWiki configuration, it's possible for an attacker to upload an SVG containing a script executed when executing the download action on the file. This problem has…

  • CVE-2021-32731MedJul 1, 2021
    risk 0.28cvss 5.3epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Between (and including) versions 13.1RC1 and 13.1, the reset password form reveals the email address of users just by giving their username. The problem has been patched on…

  • CVE-2024-46979MedSep 18, 2024
    risk 0.27cvss 5.3epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to get access to notification filters of any user by using a URL such as `xwiki/bin/get/XWiki/Notifications/Code/NotificationFilterPreferenceLivetableR…

  • CVE-2022-41929MedNov 23, 2022
    risk 0.25cvss 4.9epss 0.01

    org.xwiki.platform:xwiki-platform-oldcore is missing authorization in User#setDisabledStatus, which may allow an incorrectly authorized user with only Script rights to enable or disable a user. This operation is meant to only be available for users with admin rights. This…

  • CVE-2023-29204MedApr 15, 2023
    risk 0.24cvss 4.7epss 0.02

    XWiki Commons are technical libraries common to several other top level XWiki projects. It is possible to bypass the existing security measures put in place to avoid open redirect by using a redirect such as `//mydomain.com` (i.e. omitting the `http:`). It was also possible to…

  • CVE-2022-23618MedFeb 9, 2022
    risk 0.24cvss 4.7epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions there is no protection against URL redirection to untrusted sites, in particular some well known parameters (xredirect) can be used to perform url…

  • CVE-2024-37898MedJul 31, 2024
    risk 0.21cvss 4.3epss 0.00

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When a user has view but not edit right on a page in XWiki, that user can delete the page and replace it by a page with new content without having delete right. The previous…

  • CVE-2023-38509MedNov 7, 2023
    risk 0.21cvss 4.3epss 0.01

    XWiki Platform is a generic wiki platform. In org.xwiki.platform:xwiki-platform-livetable-ui starting with version 3.5-milestone-1 and prior to versions 14.10.9 and 15.3-rc-1, the mail obfuscation configuration was not fully taken into account and is was still possible by…

  • CVE-2022-36095MedSep 8, 2022
    risk 0.21cvss 4.3epss 0.00

    XWiki Platform is a generic wiki platform. Prior to versions 13.10.5 and 14.3, it is possible to perform a Cross-Site Request Forgery (CSRF) attack for adding or removing tags on XWiki pages. The problem has been patched in XWiki 13.10.5 and 14.3. As a workaround, one may…

  • CVE-2025-32971LowApr 30, 2025
    risk 0.18cvss 3.8epss 0.00

    XWiki is a generic wiki platform. In versions starting from 4.5.1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0-rc-1, the Solr script service doesn't take dropped programming rights into account. The Solr script service that is…

  • CVE-2023-29203LowApr 15, 2023
    risk 0.17cvss 3.7epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. It's possible to list some users who are normally not viewable from subwiki by requesting users on a subwiki which allows only global users with `uorgsuggest.vm`. This issue only concerns…

  • CVE-2025-49583LowJun 13, 2025
    risk 0.16cvss 3.5epss 0.00

    XWiki is a generic wiki platform. When a user without script right creates a document with an `XWiki.Notifications.Code.NotificationEmailRendererClass` object, and later an admin edits and saves that document, the email templates in this object will be used for notifications. No…

Page 12 of 13