VYPR

Vendor CVEs

Cryptpad

All CVEs

299 total · sorted by risk
  • CVE-2025-46554MedApr 30, 2025
    risk 0.28cvss 5.3epss 0.01

    XWiki is a generic wiki platform. In versions starting from 1.8.1 to before 14.10.22, from 15.0-rc-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.7.0, anyone can access the metadata of any attachment in the wiki using the wiki…

  • CVE-2025-29925MedMar 19, 2025
    risk 0.28cvss 5.3epss 0.01

    XWiki Platform is a generic wiki platform. Prior to 15.10.14, 16.4.6, and 16.10.0-rc-1, protected pages are listed when requesting the REST endpoints /rest/wikis/[wikiName]/pages even if the user doesn't have view rights on them. It's particularly true if the entire wiki is…

  • CVE-2024-55876MedDec 12, 2024
    risk 0.28cvss 5.4epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0, any user with an account on the main wiki could run scheduling operations on subwikis. To reproduce, as a user on the main wiki without any special right,…

  • CVE-2024-45591MedSep 10, 2024
    risk 0.28cvss 5.3epss 0.03

    XWiki Platform is a generic wiki platform. The REST API exposes the history of any page in XWiki of which the attacker knows the name. The exposed information includes for each modification of the page the time of the modification, the version number, the author of the…

  • CVE-2024-31985MedApr 10, 2024
    risk 0.28cvss 5.4epss 0.00

    XWiki Platform is a generic wiki platform. Starting in version 3.1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, it is possible to schedule/trigger/unschedule existing jobs by having an admin visit the Job Scheduler page through a predictable URL, for example by…

  • CVE-2023-34466MedJun 23, 2023
    risk 0.28cvss 4.3epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 5.0-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, tags from pages not viewable to the current user are leaked by the tags API. This…

  • CVE-2023-32068MedMay 15, 2023
    risk 0.28cvss 4.7epss 0.55

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 14.10.4 it's possible to exploit well known parameters in XWiki URLs to perform redirection to untrusted site. This vulnerability was partially fixed in…

  • CVE-2023-29520MedApr 19, 2023
    risk 0.28cvss 4.3epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to break many translations coming from wiki pages by creating a corrupted document containing a translation object. This will lead to a broken page. The…

  • CVE-2023-29506MedApr 16, 2023
    risk 0.28cvss 5.4epss 0.02

    XWiki Commons are technical libraries common to several other top level XWiki projects. It was possible to inject some code using the URL of authenticated endpoints. This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10.

  • CVE-2023-26056MedMar 2, 2023
    risk 0.28cvss 5.4epss 0.01

    XWiki Platform is a generic wiki platform. Starting in version 3.0-milestone-1, it's possible to execute a script with the right of another user, provided the target user does not have programming right. The problem has been patched in XWiki 14.8-rc-1, 14.4.5, and 13.10.10.…

  • CVE-2022-41935MedNov 23, 2022
    risk 0.28cvss 5.3epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users without the right to view documents can deduce their existence by repeated Livetable queries. The issue has been patched in XWiki 14.6RC1, 13.10.8, and 14.4.3, the…

  • CVE-2022-41936MedNov 22, 2022
    risk 0.28cvss 5.3epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The `modifications` rest endpoint does not filter out entries according to the user's rights. Therefore, information hidden from unauthorized users are exposed though the…

  • CVE-2022-29161MedMay 6, 2022
    risk 0.28cvss 5.4epss 0.00

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The XWiki Crypto API will generate X509 certificates signed by default using SHA1 with RSA, which is not considered safe anymore for use in certificate signatures, due to the…

  • CVE-2022-23619MedFeb 9, 2022
    risk 0.28cvss 5.3epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to guess if a user has an account on the wiki by using the "Forgot your password" form, even if the wiki is closed to guest users. This…

  • CVE-2022-23615MedFeb 9, 2022
    risk 0.28cvss 5.4epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can save a document with the right of the current user which allow accessing API requiring programming right if the current…

  • CVE-2021-43841MedFeb 4, 2022
    risk 0.28cvss 5.4epss 0.01

    XWiki is a generic wiki platform offering runtime services for applications built on top of it. When using default XWiki configuration, it's possible for an attacker to upload an SVG containing a script executed when executing the download action on the file. This problem has…

  • CVE-2021-32731MedJul 1, 2021
    risk 0.28cvss 5.3epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Between (and including) versions 13.1RC1 and 13.1, the reset password form reveals the email address of users just by giving their username. The problem has been patched on…

  • CVE-2025-65090MedJan 10, 2026
    risk 0.27cvss 5.3epss 0.00

    XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights to view the Calendar.JSONService page (including guest users) can exploit the data leak vulnerability by accessing database info, with the exception of…

  • CVE-2025-54990MedNov 18, 2025
    risk 0.27cvss 5.3epss 0.00

    XWiki AdminTools integrates administrative tools for managing a running XWiki instance. Prior to version 1.1, users without admin rights have access to AdminTools.SpammedPages. View rights are not restricted only to admin users for AdminTools.SpammedPages. While no data is…

  • CVE-2024-46979MedSep 18, 2024
    risk 0.27cvss 5.3epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to get access to notification filters of any user by using a URL such as `xwiki/bin/get/XWiki/Notifications/Code/NotificationFilterPreferenceLivetableR…

  • CVE-2024-26138MedFeb 21, 2024
    risk 0.27cvss 5.3epss 0.00

    The XWiki licensor application, which manages and enforce application licenses for paid extensions, includes the document `Licenses.Code.LicenseJSON` that provides information for admins regarding active licenses. This document is public and thus exposes this information…

  • CVE-2023-37465medJul 27, 2026
    risk 0.26cvss epss

    ### Impact It's possible to forge a request to delete a message. ### Patches The problem has been patched in version 2.0-rc-1 of Discussion Extension. ### Workarounds There's no easy workaround except upgrading. ### References https://jira.xwiki.org/browse/DISCUSSION-22 ###…

  • CVE-2022-41929MedNov 23, 2022
    risk 0.25cvss 4.9epss 0.01

    org.xwiki.platform:xwiki-platform-oldcore is missing authorization in User#setDisabledStatus, which may allow an incorrectly authorized user with only Script rights to enable or disable a user. This operation is meant to only be available for users with admin rights. This…

  • CVE-2022-24898MedApr 28, 2022
    risk 0.25cvss 4.9epss 0.01

    org.xwiki.commons:xwiki-commons-xml is a common module used by other XWiki top level projects. Starting in version 2.7 and prior to versions 12.10.10, 13.4.4, and 13.8-rc-1, it is possible for a script to access any file accessing to the user running XWiki application server…

  • CVE-2023-29204MedApr 15, 2023
    risk 0.24cvss 4.7epss 0.02

    XWiki Commons are technical libraries common to several other top level XWiki projects. It is possible to bypass the existing security measures put in place to avoid open redirect by using a redirect such as `//mydomain.com` (i.e. omitting the `http:`). It was also possible to…

  • CVE-2022-23618MedFeb 9, 2022
    risk 0.24cvss 4.7epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions there is no protection against URL redirection to untrusted sites, in particular some well known parameters (xredirect) can be used to perform url…

  • CVE-2024-37898MedJul 31, 2024
    risk 0.21cvss 4.3epss 0.00

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When a user has view but not edit right on a page in XWiki, that user can delete the page and replace it by a page with new content without having delete right. The previous…

  • CVE-2023-38509MedNov 7, 2023
    risk 0.21cvss 4.3epss 0.01

    XWiki Platform is a generic wiki platform. In org.xwiki.platform:xwiki-platform-livetable-ui starting with version 3.5-milestone-1 and prior to versions 14.10.9 and 15.3-rc-1, the mail obfuscation configuration was not fully taken into account and is was still possible by…

  • CVE-2022-36095MedSep 8, 2022
    risk 0.21cvss 4.3epss 0.00

    XWiki Platform is a generic wiki platform. Prior to versions 13.10.5 and 14.3, it is possible to perform a Cross-Site Request Forgery (CSRF) attack for adding or removing tags on XWiki pages. The problem has been patched in XWiki 13.10.5 and 14.3. As a workaround, one may…

  • CVE-2025-32971LowApr 30, 2025
    risk 0.18cvss 3.8epss 0.00

    XWiki is a generic wiki platform. In versions starting from 4.5.1 to before 15.10.13, from 16.0.0-rc-1 to before 16.4.4, and from 16.5.0-rc-1 to before 16.8.0-rc-1, the Solr script service doesn't take dropped programming rights into account. The Solr script service that is…

  • CVE-2023-29203LowApr 15, 2023
    risk 0.17cvss 3.7epss 0.01

    XWiki Commons are technical libraries common to several other top level XWiki projects. It's possible to list some users who are normally not viewable from subwiki by requesting users on a subwiki which allows only global users with `uorgsuggest.vm`. This issue only concerns…

  • CVE-2025-49583LowJun 13, 2025
    risk 0.16cvss 3.5epss 0.00

    XWiki is a generic wiki platform. When a user without script right creates a document with an `XWiki.Notifications.Code.NotificationEmailRendererClass` object, and later an admin edits and saves that document, the email templates in this object will be used for notifications. No…

  • CVE-2021-32729LowJul 1, 2021
    risk 0.13cvss 2.0epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A vulnerability exists in versions prior to 12.6.88, 12.10.4, and 13.0. The script service method used to reset the authentication failures record can be executed by any user…

  • CVE-2025-32972LowApr 30, 2025
    risk 0.11cvss 2.7epss 0.00

    XWiki is a generic wiki platform. In versions starting from 6.1-milestone-1 to before 15.10.12, from 16.0.0-rc-1 to before 16.4.3, and from 16.5.0-rc-1 to before 16.8.0-rc-1, the script API of the LESS compiler in XWiki is incorrectly checking for rights when calling the cache…

  • CVE-2022-29253LowMay 25, 2022
    risk 0.11cvss 2.7epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with version 8.3-rc-1 and prior to versions 12.10.3 and 14.0, one can ask for any file located in the classloader using the template API and a path with ".." in it.…

  • CVE-2025-55728CriSep 9, 2025
    risk 0.00cvss 10.0epss 0.01

    XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the classes parameter in the panel macro allows remote code execution for any user who can edit…

  • CVE-2025-55727CriSep 9, 2025
    risk 0.00cvss 10.0epss 0.01

    XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the width parameter in the column macro allows remote code execution for any user who can edit any…

  • CVE-2025-49591CriJun 18, 2025
    risk 0.00cvss 9.1epss 0.00

    CryptPad is a collaboration suite. Prior to version 2025.3.0, enforcement of Two-Factor Authentication (2FA) in CryptPad can be trivially bypassed, due to weak implementation of access controls. An attacker that compromises a user's credentials can gain access to the victim's…

  • CVE-2025-49590MedJun 18, 2025
    risk 0.00cvss 6.1epss 0.00

    CryptPad is a collaboration suite. Prior to version 2025.3.0, the "Link Bouncer" functionality attempts to filter javascript URIs to prevent Cross-Site Scripting (XSS), however this can be bypassed. There is an "early allow" code path that happens before the URI's…

  • CVE-2024-42489CriAug 12, 2024
    risk 0.00cvss 10.0epss 0.01

    Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` page or edit or comment right on any page to perform remote code execution. Other macros like Viewppt are vulnerable to the same kind…

  • CVE-2020-13654HigDec 31, 2020
    risk 0.00cvss 7.5epss 0.02

    XWiki Platform before 12.8 mishandles escaping in the property displayer.

  • CVE-2012-1019Feb 8, 2012
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in XWiki Enterprise 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) XWiki.XWikiComments_comment parameter to xwiki/bin/commentadd/Main/WebHome, (2) XWiki.XWikiUsers_0_company parameter when editing…

  • CVE-2010-4642Dec 30, 2010
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in XWiki Enterprise before 2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2010-4641Dec 30, 2010
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in XWiki Enterprise before 2.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

  • CVE-2010-4640Dec 30, 2010
    risk 0.00cvss epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in XWiki Watch 1.0 allow remote attackers to inject arbitrary web script or HTML via the rev parameter to (1) bin/viewrev/Main/WebHome and (2) bin/view/Blog, and the (3) register_first_name and (4) register_last_name parameters…

  • CVE-2007-4898Sep 14, 2007
    risk 0.00cvss epss 0.01

    Unspecified vulnerability in the Multiwiki plugin in XWiki before 1.1 Enterprise RC2 allows remote authenticated users, with administrative access to one wiki in a multiwiki environment, to obtain sensitive information via unknown attack vectors. NOTE: Some of these details are…

  • CVE-2006-7223Sep 14, 2007
    risk 0.00cvss epss 0.02

    PreviewAction in XWiki 0.9.543 through 0.9.1252 does not set the Author field to the identity of the user who last modified a document, which allows remote authenticated users without programming rights to execute arbitrary code by selecting a document whose author has…

  • CVE-2007-4888Sep 14, 2007
    risk 0.00cvss epss 0.01

    The "You are not allowed..." error handler in XWiki 1.0 B1 and 1.0 B2 associates the doc variable with the entire document content and metadata regardless of a user's view rights, which allows remote authenticated users to read arbitrary documents via a custom skin that prints…

  • CVE-2005-4862Dec 31, 2005
    risk 0.00cvss epss 0.01

    The search functionality in XWiki 0.9.793 indexes cleartext user passwords, which allows remote attackers to obtain sensitive information via a search string that matches a password.

Page 6 of 6