VYPR

Xwiki

by Cryptpad

Source repositories

CVEs (251)

  • CVE-2022-41931CriNov 23, 2022
    risk 0.57cvss 9.9epss 0.01

    xwiki-platform-icon-ui is vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection'). Any user with view rights on commonly accessible documents including the icon picker macro can execute arbitrary Groovy, Python or Velocity code in…

  • CVE-2022-36098HigSep 8, 2022
    risk 0.57cvss 8.9epss 0.71

    XWiki Platform Mentions UI is a user interface for mentioning users in wiki content for XWiki Platform, a generic wiki platform. Starting in version 12.5-rc-1 and prior to versions 13.10.6 and 14.4, it's possible to store Javascript or groovy scripts in a mention, macro anchor,…

  • CVE-2023-46732CriNov 6, 2023
    risk 0.56cvss 9.6epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to reflected cross-site scripting (RXSS) via the `rev` parameter that is used in the content of the content menu without escaping. If an attacker can…

  • CVE-2023-45136CriOct 25, 2023
    risk 0.56cvss 9.6epss 0.05

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When document names are validated according to a name strategy (disabled by default), XWiki starting in version 12.0-rc-1 and prior to versions 12.10.12 and 15.5-rc-1 is…

  • CVE-2023-35162CriJun 23, 2023
    risk 0.56cvss 9.6epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the previewactions template to perform a XSS, e.g. by…

  • CVE-2023-35161CriJun 23, 2023
    risk 0.56cvss 9.6epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the DeleteApplication page to perform a XSS, e.g. by…

  • CVE-2023-35160CriJun 23, 2023
    risk 0.56cvss 9.6epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the resubmit template to perform a XSS, e.g. by using…

  • CVE-2023-35159CriJun 23, 2023
    risk 0.56cvss 9.6epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the deletespace template to perform a XSS, e.g. by…

  • CVE-2023-35158CriJun 23, 2023
    risk 0.56cvss 9.6epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the restore template to perform a XSS, e.g. by using…

  • CVE-2023-35156CriJun 23, 2023
    risk 0.56cvss 9.6epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the delete template to perform a XSS, e.g. by using…

  • CVE-2022-36096HigSep 8, 2022
    risk 0.56cvss 8.9epss 0.59

    The XWiki Platform Index UI is an Index of all pages, attachments, orphans and deleted pages and attachments for XWiki Platform, a generic wiki platform. Prior to versions 13.10.6 and 14.3, it's possible to store JavaScript which will be executed by anyone viewing the deleted…

  • CVE-2022-36094HigSep 8, 2022
    risk 0.56cvss 8.9epss 0.64

    XWiki Platform Web Parent POM contains Web resources for the XWiki platform, a generic wiki platform. Starting with version 1.0 and prior to versions 13.10.6 and 14.30-rc-1, it's possible to store JavaScript which will be executed by anyone viewing the history of an attachment…

  • CVE-2020-15252HigOct 16, 2020
    risk 0.56cvss 8.5epss 0.03

    In XWiki before version 12.5 and 11.10.6, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet context which contains tools allowing to instantiate arbitrary Java objects and invoke methods that may lead to arbitrary code…

  • CVE-2024-41947CriJul 31, 2024
    risk 0.55cvss 9.0epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a conflict when another user with more rights is currently editing a page, it is possible to execute JavaScript snippets on the side of the other user, which…

  • CVE-2024-31988CriApr 10, 2024
    risk 0.55cvss 9.6epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 13.9-rc-1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, when the realtime editor is installed in XWiki, it allows arbitrary remote code execution with the interaction of an admin user with programming right.…

  • CVE-2023-50722CriDec 15, 2023
    risk 0.55cvss 9.6epss 0.01

    XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, there is a reflected XSS or also direct remote code execution vulnerability in the code for displaying configurable admin sections. The code that can be passed…

  • CVE-2023-46242CriNov 7, 2023
    risk 0.55cvss 9.6epss 0.00

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to execute a content with the right of any user via a crafted URL. A user must have `programming` privileges in order to exploit this…

  • CVE-2023-37277CriJul 10, 2023
    risk 0.55cvss 9.6epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The REST API allows executing all actions via POST requests and accepts `text/plain`, `multipart/form-data` or `application/www-form-urlencoded` as content types which can be…

  • CVE-2022-41937CriNov 22, 2022
    risk 0.55cvss 9.6epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application allows anyone with view access to modify any page of the wiki by importing a crafted XAR package. The problem has been patched in XWiki 14.6RC1, 14.6 and…

  • CVE-2022-36097HigSep 8, 2022
    risk 0.55cvss 8.9epss 0.57

    XWiki Platform Attachment UI provides a macro to easily upload and select attachments for XWiki Platform, a generic wiki platform. Starting with version 14.0-rc-1 and prior to 14.4-rc-1, it's possible to store JavaScript in an attachment name, which will be executed by anyone…

Page 5 of 13