VYPR

Xwiki

by Cryptpad

Source repositories

CVEs (251)

  • CVE-2023-32070CriMay 10, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki syntax. This has been patched in…

  • CVE-2023-31126CriMay 9, 2023
    risk 0.52cvss 9.0epss 0.01

    `org.xwiki.commons:xwiki-commons-xml` is an XML library used by the open-source wiki platform XWiki. The HTML sanitizer, introduced in version 14.6-rc-1, allows the injection of arbitrary HTML code and thus cross-site scripting via invalid data attributes. This vulnerability…

  • CVE-2023-29519CriApr 19, 2023
    risk 0.52cvss 9.0epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A registered user can perform remote code execution leading to privilege escalation by injecting the proper code in the "property" field of an attachment selector, as a…

  • CVE-2023-29213CriApr 17, 2023
    risk 0.52cvss 9.0epss 0.00

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of `org.xwiki.platform:xwiki-platform-logging-ui` it is possible to trick a user with programming rights into visiting a constructed url where e.g., by…

  • CVE-2023-29507CriApr 16, 2023
    risk 0.52cvss 9.1epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. The Document script API returns directly a DocumentAuthors allowing to set any authors to the document, which in consequence can allow subsequent executions of scripts since this author is…

  • CVE-2023-29206CriApr 15, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. There was no check in the author of a JavaScript xobject or StyleSheet xobject added in a XWiki document, so until now it was possible for a user having only Edit Right to create such object…

  • CVE-2023-29202CriApr 15, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. The RSS macro that is bundled in XWiki included the content of the feed items without any cleaning in the HTML output when the parameter `content` was set to `true`. This allowed arbitrary…

  • CVE-2023-29201CriApr 15, 2023
    risk 0.52cvss 9.0epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1, only escaped `` and ``-tags but neither attributes that can be used to inject scripts…

  • CVE-2023-29207HigApr 15, 2023
    risk 0.51cvss 8.9epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. The Livetable Macro wasn't properly sanitizing column names, thus allowing the insertion of raw HTML code including JavaScript. This vulnerability was also exploitable via the Documents…

  • CVE-2023-26480HigMar 2, 2023
    risk 0.51cvss 8.9epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 12.10, a user without script rights can introduce a stored cross-site scripting by using the Live Data macro. This has been patched in XWiki 14.9, 14.4.7, and 13.10.10. There are no known workarounds.

  • CVE-2025-49586HigJun 13, 2025
    risk 0.50cvss 8.8epss 0.01

    XWiki is an open-source wiki software platform. Any XWiki user with edit right on at least one App Within Minutes application (the default for all users XWiki) can obtain programming right/perform remote code execution by editing the application. This vulnerability has been…

  • CVE-2025-49581HigJun 13, 2025
    risk 0.50cvss 8.8epss 0.01

    XWiki is a generic wiki platform. Any user with edit right on a page (could be the user's profile) can execute code (Groovy, Python, Velocity) with programming right by defining a wiki macro. This allows full access to the whole XWiki installation. The main problem is that if a…

  • CVE-2025-48063HigMay 21, 2025
    risk 0.50cvss 8.8epss 0.01

    XWiki is a generic wiki platform. In XWiki 16.10.0, required rights were introduced as a way to limit which rights a document can have. Part of the security model of required rights is that a user who doesn't have a right also cannot define that right as required right. That…

  • CVE-2023-48293HigNov 20, 2023
    risk 0.50cvss 8.8epss 0.00

    The XWiki Admin Tools Application provides tools to help the administration of XWiki. Prior to version 4.5.1, a cross-site request forgery vulnerability in the query on XWiki tool allows executing arbitrary database queries on the database of the XWiki installation. Among other…

  • CVE-2023-35155HigJun 23, 2023
    risk 0.50cvss 8.8epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). For instance, the following URL execute an `alter` on the browser:…

  • CVE-2022-23616HigFeb 9, 2022
    risk 0.50cvss 8.8epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for an unprivileged user to perform a remote code execution by injecting a groovy script in her own profile and by calling the Reset…

  • CVE-2021-32621HigMay 28, 2021
    risk 0.50cvss 8.8epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 12.6.7 and 12.10.3, a user without Script or Programming right is able to execute script requiring privileges by editing gadget titles in the dashboard.…

  • CVE-2021-32620HigMay 28, 2021
    risk 0.50cvss 8.8epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 11.10.13, 12.6.7, and 12.10.2, a user disabled on a wiki using email verification for registration canouldre-activate themself by using the activation…

  • CVE-2021-21380HigMar 23, 2021
    risk 0.50cvss 7.7epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of XWiki Platform (and only those with the Ratings API installed), the Rating Script Service expose an API to perform SQL requests without escaping the…

  • CVE-2021-21379HigMar 12, 2021
    risk 0.50cvss 7.7epss 0.00

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of XWiki Platform, the `{{wikimacrocontent}}` executes the content with the rights of the wiki macro author instead of the caller of that wiki macro.…

Page 7 of 13