VYPR
Vendor

Cryptpad

Products
46
CVEs
299
Across products
559
Status
Private

Products

46
View all 46 products →

Recent CVEs

299
View all 299 CVEs →
  • CVE-2025-24893CriKEVFeb 20, 2025
    risk 0.80cvss 9.8epss 1.00

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity and availability of the whole XWiki…

  • CVE-2023-29524CriApr 19, 2023
    risk 0.70cvss 9.9epss 0.76

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute anything with the right of the Scheduler Application sheet page. A user without script or programming rights, edit your user profile with the object…

  • CVE-2025-32429CriJul 24, 2025
    risk 0.67cvss 9.8epss 0.85

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. It's…

  • CVE-2024-21650CriJan 8, 2024
    risk 0.65cvss 10.0epss 0.93

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code execution (RCE) attack through its user registration feature. This issue allows an attacker to execute arbitrary code by crafting…

  • CVE-2023-46731CriNov 6, 2023
    risk 0.65cvss 10.0epss 0.89

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki doesn't properly escape the section URL parameter that is used in the code for displaying administration sections. This allows any user with read access to the document…

  • CVE-2023-37462CriJul 14, 2023
    risk 0.65cvss 9.9epss 0.91

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode.XWikiSkinsSheet` leads to an injection vector from view right on that document to programming rights, or in other words, it is…

  • CVE-2020-11057CriMay 12, 2020
    risk 0.65cvss 9.9epss 0.02

    In XWiki Platform 7.2 through 11.10.2, registered users without scripting/programming permissions are able to execute python/groovy scripts while editing personal dashboards. This has been fixed 11.3.7 , 11.10.3 and 12.0.

  • CVE-2024-31984CriApr 10, 2024
    risk 0.64cvss 9.9epss 0.83

    XWiki Platform is a generic wiki platform. Starting in version 7.2-rc-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, by creating a document with a specially crafted title, it is possible to trigger remote code execution in the (Solr-based) search in XWiki. This allows…

  • CVE-2023-50721CriDec 15, 2023
    risk 0.64cvss 9.9epss 0.79

    XWiki Platform is a generic wiki platform. Starting in 4.5-rc-1 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the search administration interface doesn't properly escape the id and label of search user interface extensions, allowing the injection of XWiki syntax…

  • CVE-2023-45138CriOct 12, 2023
    risk 0.64cvss 10.0epss 0.71

    Change Request is an pplication allowing users to request changes on a wiki without publishing the changes directly. Starting in version 0.11 and prior to version 1.9.2, it's possible for a user without any specific right to perform script injection and remote code execution…

  • CVE-2023-36469CriJun 29, 2023
    risk 0.64cvss 9.9epss 0.82

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile and notification settings can execute arbitrary script macros including Groovy and Python macros that allow remote code execution…

  • CVE-2023-35150CriJun 23, 2023
    risk 0.64cvss 9.9epss 0.78

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to versions 14.4.8, 14.10.4, and 15.0, any user with view rights on any document can execute code with programming rights, leading to…

  • CVE-2023-29527CriApr 19, 2023
    risk 0.64cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions a user without script or programming right may edit a user profile (or any other document) with the wiki editor and add groovy script content. Viewing…

  • CVE-2023-29526CriApr 19, 2023
    risk 0.64cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to display or interact with any page a user cannot access through the combination of the async and display macros. A comment with either…

  • CVE-2023-29525CriApr 19, 2023
    risk 0.64cvss 9.9epss 0.78

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Affected versions of xwiki are subject to code injection in the `since` parameter of the `/xwiki/bin/view/XWiki/Notifications/Code/LegacyNotificationAdministration` endpoint.…

  • CVE-2023-29205CriApr 15, 2023
    risk 0.64cvss 9.9epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. The HTML macro does not systematically perform a proper neutralization of script-related html tags. As a result, any user able to use the html macro in XWiki, is able to introduce an XSS…

  • CVE-2023-26474CriMar 2, 2023
    risk 0.64cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing document content author to execute a text area property. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11. There are no known workarounds.

  • CVE-2023-26055CriMar 2, 2023
    risk 0.64cvss 9.9epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. Starting in version 3.1-milestone-1, any user can edit their own profile and inject code, which is going to be executed with programming right. The same vulnerability can also be exploited in…

  • CVE-2023-26477CriMar 2, 2023
    risk 0.64cvss 10.0epss 0.75

    XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script macros via the `newThemeName` request parameter (URL parameter), in combination with additional…

  • CVE-2022-41928CriNov 23, 2022
    risk 0.64cvss 9.9epss 0.01

    XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in AttachmentSelector.xml. The issue can also be reproduced by inserting the dangerous payload in the `height` or `alt` macro properties. This has been patched in…

VYPR — Vulnerability Intelligence