VYPR

Vendor CVEs

Cryptpad

All CVEs

299 total · sorted by risk
  • CVE-2023-26476HigMar 2, 2023
    risk 0.42cvss 7.5epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 3.2-m3, users can deduce the content of the password fields by repeated call to `LiveTableResults` and `WikisLiveTableResultsMacros`. The issue can be fixed by upgrading to versions 14.7-rc-1, 13.4.4, or 13.10.9 and…

  • CVE-2023-26473MedMar 2, 2023
    risk 0.42cvss 6.5epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 1.3-rc-1, any user with edit right can execute arbitrary database select and access data stored in the database. The problem has been patched in XWiki 13.10.11, 14.4.7, and 14.10. There is no workaround for this…

  • CVE-2022-41930HigNov 23, 2022
    risk 0.42cvss 7.5epss 0.01

    org.xwiki.platform:xwiki-platform-user-profile-ui is missing authorization to enable or disable users. Any user (logged in or not) with access to the page XWiki.XWikiUserProfileSheet can enable or disable any user profile. This might allow to a disabled user to re-enable…

  • CVE-2022-36092HigSep 8, 2022
    risk 0.42cvss 7.5epss 0.01

    XWiki Platform Old Core is a core package for XWiki Platform, a generic wiki platform. Prior to versions 14.2 and 13.10.4, all rights checks that would normally prevent a user from viewing a document on a wiki can be bypassed using the login action and directly specified…

  • CVE-2022-24897HigMay 2, 2022
    risk 0.42cvss 7.5epss 0.02

    APIs to evaluate content with Velocity is a package for APIs to evaluate content with Velocity. Starting with version 2.3 and prior to 12.6.7, 12.10.3, and 13.0, the velocity scripts are not properly sandboxed against using the Java File API to perform read or write operations…

  • CVE-2021-32732HigFeb 4, 2022
    risk 0.42cvss 7.5epss 0.01

    ### Impact It's possible to know if a user has or not an account in a wiki related to an email address, and which username(s) is actually tied to that email by forging a request to the Forgot username page. Note that since this page does not have a CSRF check it's quite easy to…

  • CVE-2019-15302MedSep 11, 2019
    risk 0.42cvss 6.5epss 0.01

    The pad management logic in XWiki labs CryptPad before 3.0.0 allows a remote attacker (who has access to a Rich Text pad with editing rights for the URL) to corrupt it (i.e., cause data loss) via a trivial URL modification.

  • CVE-2022-41927HigNov 23, 2022
    risk 0.41cvss 7.4epss 0.00

    XWiki Platform is vulnerable to Cross-Site Request Forgery (CSRF) that may allow attackers to delete or rename tags without needing any confirmation. The problem has been patched in XWiki 13.10.7, 14.4.1 and 14.5RC1. Workarounds: It's possible to patch existing instances…

  • CVE-2022-29258HigMay 31, 2022
    risk 0.41cvss 7.4epss 0.01

    XWiki Platform Filter UI provides a generic user interface to convert from a XWiki Filter input stream to an output stream with settings for each stream. Starting with versions 6.0-milestone-2 and 5.4.4 and prior to versions 12.10.11, 14.0-rc-1, 13.4.7, and 13.10.3, XWiki…

  • CVE-2022-29252HigMay 25, 2022
    risk 0.41cvss 7.4epss 0.01

    XWiki Platform Wiki UI Main Wiki is a package for managing subwikis. Starting with version 5.3-milestone-2, XWiki Platform Wiki UI Main Wiki contains a possible cross-site scripting vector in the `WikiManager.JoinWiki ` wiki page related to the "requestJoin" field. The issue is…

  • CVE-2022-29251HigMay 25, 2022
    risk 0.41cvss 7.4epss 0.01

    XWiki Platform Flamingo Theme UI is a tool that allows customization and preview of any Flamingo-based skin. Starting with versions 6.2.4 and 6.3-rc-1, a possible cross-site scripting vector is present in the `FlamingoThemesCode.WebHomeSheet` wiki page related to the…

  • CVE-2022-23622HigFeb 9, 2022
    risk 0.41cvss 7.4epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions there is a cross site scripting (XSS) vector in the `registerinline.vm` template related to the `xredirect` hidden field. This template is only used in…

  • CVE-2017-1000051MedJul 17, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in pad export in XWiki labs CryptPad before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the pad content

  • CVE-2025-65089MedNov 19, 2025
    risk 0.37cvss 6.8epss 0.00

    XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to version 1.27.0, a user with no view rights on a page may see the content of an office attachment displayed with the view file macro. This issue has been patched…

  • CVE-2024-31464MedApr 10, 2024
    risk 0.37cvss 6.8epss 0.00

    XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.19, 15.5.4, and 15.9-rc-1, it is possible to access the hash of a password by using the diff feature of the history whenever the object storing the password is deleted. Using that…

  • CVE-2022-23620MedFeb 9, 2022
    risk 0.37cvss 6.8epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions AbstractSxExportURLFactoryActionHandler#processSx does not escape anything from SSX document references when serializing it on filesystem, it is possible…

  • CVE-2024-37900MedJul 31, 2024
    risk 0.36cvss 6.4epss 0.16

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When uploading an attachment with a malicious filename, malicious JavaScript code could be executed. This requires a social engineering attack to get the victim into…

  • CVE-2023-26478MedMar 2, 2023
    risk 0.36cvss 6.6epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 14.3-rc-1, `org.xwiki.store.script.TemporaryAttachmentsScriptService#uploadTemporaryAttachment` returns an instance of `com.xpn.xwiki.doc.XWikiAttachment`. This class is not supported to be exposed to users without…

  • CVE-2025-54125MedAug 6, 2025
    risk 0.35cvss 6.5epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 1.1 through 16.4.6, 16.5.0-rc-1 through 16.10.4 and 17.0.0-rc-1 through 17.1.0, the XML export of a page…

  • CVE-2025-54124MedAug 6, 2025
    risk 0.35cvss 6.5epss 0.00

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 9.8-rc-1 through 16.4.6, 16.5.0-rc-1 through 16.10.4, and 17.0.0-rc-1 through 17.1.0, any user with…

  • CVE-2025-52133MedAug 3, 2025
    risk 0.35cvss 6.4epss 0.00

    The Mocca Calendar application before 2.15 for XWiki allows XSS via a title upon calendar import.

  • CVE-2025-52132MedAug 3, 2025
    risk 0.35cvss 6.4epss 0.00

    The Mocca Calendar application before 2.15 for XWiki allows XSS via a title to the view event page.

  • CVE-2025-52131MedAug 3, 2025
    risk 0.35cvss 6.4epss 0.00

    The Mocca Calendar application before 2.15 for XWiki allows XSS via the background or text color field.

  • CVE-2024-46978MedSep 18, 2024
    risk 0.35cvss 6.5epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible for any user knowing the ID of a notification filter preference of another user, to enable/disable it or even delete it. The impact is that the target user…

  • CVE-2023-37911MedOct 25, 2023
    risk 0.35cvss 6.5epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 9.4-rc-1 and prior to versions 14.10.8 and 15.3-rc-1, when a document has been deleted and re-created, it is possible for users with view right on the…

  • CVE-2023-26479MedMar 2, 2023
    risk 0.35cvss 6.5epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 6.0, users with write rights can insert well-formed content that is not handled well by the parser. As a consequence, some pages becomes unusable, including the user index (if the page containing the faulty content…

  • CVE-2022-24820MedApr 8, 2022
    risk 0.35cvss 5.3epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents by rendering some velocity documents. The problem has been patched in XWiki versions…

  • CVE-2022-24819MedApr 8, 2022
    risk 0.35cvss 5.3epss 0.03

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents related to users of the wiki. The problem has been patched in XWiki versions 12.10.11,…

  • CVE-2022-23617MedFeb 9, 2022
    risk 0.35cvss 6.5epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit right can copy the content of a page it does not have access to by using it as template of a new page. This issue has been patched in…

  • CVE-2021-3137MedJan 20, 2021
    risk 0.35cvss 5.4epss 0.01

    XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.

  • CVE-2018-16277MedSep 28, 2018
    risk 0.35cvss 5.4epss 0.01

    The Image Import function in XWiki through 10.7 has XSS.

  • CVE-2023-41046MedSep 1, 2023
    risk 0.34cvss 6.3epss 0.00

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible in XWiki to execute Velocity code without having script right by creating an XClass with a property of type "TextArea" and content type "VelocityCode" or…

  • CVE-2026-26028MedMay 20, 2026
    risk 0.33cvss 6.1epss 0.00

    CryptPad is an end-to-end encrypted collaborative office suite. In versions prior to 2026.2.0, the HTML sanitizer in Diffmarked.js can be bypassed due to incomplete attribute filtering on restricted tags. The sanitizer validates only the src attribute of , , and…

  • CVE-2026-40105MedApr 15, 2026
    risk 0.33cvss 6.1epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 10.4-rc-1, through 16.10.15, 17.0.0-rc-1, through 17.4.7 and 17.5.0-rc-1 through 17.10.0 contain a reflected cross-site scripting vulnerability (XSS) in the…

  • CVE-2026-26000MedFeb 12, 2026
    risk 0.33cvss 6.1epss 0.00

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.9.0, 17.4.6, and 16.10.13, it's possible using comments to inject CSS that would transform the full wiki in a link area leading to a malicious page. This…

  • CVE-2026-24128MedJan 24, 2026
    risk 0.33cvss 6.1epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 7.0-milestone-2 through 16.10.11, 17.0.0-rc-1 through 17.4.4, and 17.5.0-rc-1 through 17.7.0 contain a reflected Cross-site Scripting (XSS) vulnerability, which…

  • CVE-2025-66472MedDec 10, 2025
    risk 0.33cvss 6.1epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 6.2-milestone-1 through 16.10.9 and 17.0.0-rc-1 through 17.4.1 of both XWiki Platform Flamingo Skin Resources and XWiki Platform Web Templates are vulnerable to a…

  • CVE-2025-32430MedAug 6, 2025
    risk 0.33cvss 6.1epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-3 through 16.4.7, 16.5.0-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, two templates contain reflected XSS vulnerabilities, allowing an…

  • CVE-2025-32970MedApr 30, 2025
    risk 0.33cvss 6.1epss 0.01

    XWiki is a generic wiki platform. In versions starting from 13.5-rc-1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0, an open redirect vulnerability in the HTML conversion request filter allows attackers to construct URLs on an XWiki…

  • CVE-2023-29513MedApr 19, 2023
    risk 0.33cvss 5.0epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. If guest has view right on any document. It's possible to create a new user using the `distribution/firstadminuser.wiki` in the wrong context. This vulnerability has been…

  • CVE-2022-41933MedNov 23, 2022
    risk 0.33cvss 6.2epss 0.00

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When the `reset a forgotten password` feature of XWiki was used, the password was then stored in plain text in database. This only concerns XWiki 13.1RC1 and newer versions.…

  • CVE-2023-50720MedDec 15, 2023
    risk 0.32cvss 5.3epss 0.59

    XWiki Platform is a generic wiki platform. Prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the email addresses of users even when obfuscation of email addresses is enabled. To demonstrate the vulnerability, search for…

  • CVE-2026-48047MedAug 7, 2026
    risk 0.31cvss epss 0.00

    XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to versions 16.10.17, 17.4.9, and 17.10.3, a potential path traversal vulnerability allow an attacker who manages to get a malicious WebJar extension installed on…

  • CVE-2025-58049MedAug 28, 2025
    risk 0.31cvss 5.8epss 0.00

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions from 14.4.2 to before 16.4.8, 16.5.0-rc-1 to before 16.10.7, and 17.0.0-rc-1 to before 17.4.0-rc-1, the PDF export jobs store sensitive cookies unencrypted in job…

  • CVE-2025-51990MedAug 20, 2025
    risk 0.31cvss 4.8epss 0.01

    XWiki through version 17.3.0 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities in the Administration interface, specifically under the Presentation section of the Global Preferences panel. An authenticated administrator can inject arbitrary JavaScript…

  • CVE-2025-32783MedApr 16, 2025
    risk 0.31cvss 4.7epss 0.00

    XWiki Platform is a generic wiki platform. A vulnerability in versions from 5.0 to 16.7.1 affects users with Message Stream enabled and a wiki configured as closed from selecting "Prevent unregistered users to view pages" in the Administrations Rights. The vulnerability is that…

  • CVE-2025-48885MedMay 30, 2025
    risk 0.30cvss epss 0.00

    application-urlshortener create shortened URLs for XWiki pages. Versions prior to 1.2.4 are vulnerable to users with view access being able to create arbitrary pages. Any user (even guests) can create these docs, even if they don't exist already. This can enable guest users to…

  • CVE-2023-26470MedMar 2, 2023
    risk 0.30cvss 5.7epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to make the farm unusable by adding an object to a page with a huge number (e.g. 67108863). Most of the time this will fill the memory allocated to XWiki and…

  • CVE-2021-32730MedJul 1, 2021
    risk 0.30cvss 5.7epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A cross-site request forgery vulnerability exists in versions prior to 12.10.5, and in versions 13.0 through 13.1. It's possible for forge an URL that, when accessed by an…

  • CVE-2022-23621MedFeb 9, 2022
    risk 0.29cvss 5.5epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can read any file located in the XWiki WAR (for example xwiki.cfg and xwiki.properties) through…

Page 5 of 6