Vulnerability index

Browse CVEs

258 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xwiki MEDIUM 5.4
CVE-2023-29206

XWiki Commons are technical libraries common to several other top level XWiki projects. There was no check in the author of a JavaScript xobject or S…

Fix: after 14.8
Fix from $1,600 2023-04-15
Xwiki MEDIUM 5.3
CVE-2023-29203

XWiki Commons are technical libraries common to several other top level XWiki projects. It's possible to list some users who are normally not viewabl…

Fix: 13.10.8 / 14.4.3+
Fix from $1,600 2023-04-15
Xwiki CRITICAL 9.0
CVE-2023-29201

XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduce…

Fix: after 14.5
Fix from $2,300 2023-04-15
Xwiki CRITICAL 9.0
CVE-2023-29202

XWiki Commons are technical libraries common to several other top level XWiki projects. The RSS macro that is bundled in XWiki included the content o…

Fix: after 14.5
Fix from $2,300 2023-04-15
Xwiki CRITICAL 9.9
CVE-2023-27479

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view righ…

Fix: 13.10.11 / 14.4.7+
Fix from $2,300 2023-03-07
Xwiki HIGH 7.7
CVE-2023-27480

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit righ…

Fix: 13.10.11 / 14.4.7+
Fix from $1,950 2023-03-07
Xwiki HIGH 8.8
CVE-2023-26471

XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the right of superadmin but in re…

Fix: 13.10.10 / 14.4.6+
Fix from $1,950 2023-03-02
Xwiki HIGH 8.8
CVE-2023-26472

XWiki Platform is a generic wiki platform. Starting in version 6.2-milestone-1, one can execute any wiki content with the right of IconThemeSheet aut…

Fix: 13.10.10 / 14.4.6+
Fix from $1,950 2023-03-02
Xwiki HIGH 8.8
CVE-2023-26474

XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing document content author to execut…

Fix: 13.10.11 / 14.4.7+
Fix from $1,950 2023-03-02
Xwiki HIGH 8.8
CVE-2023-26475EPSS 64%

XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted…

Fix: 13.10.11 / 14.4.7+
Fix from $1,950 2023-03-02
Xwiki HIGH 7.5
CVE-2023-26470

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to make the farm unusable by a…

Fix: 14.0+
Fix from $1,950 2023-03-02
Xwiki HIGH 7.5
CVE-2023-26476

XWiki Platform is a generic wiki platform. Starting in version 3.2-m3, users can deduce the content of the password fields by repeated call to `LiveT…

Fix: 13.4.4 / 13.10.9+
Fix from $1,950 2023-03-02
Xwiki MEDIUM 6.5
CVE-2023-26473

XWiki Platform is a generic wiki platform. Starting in version 1.3-rc-1, any user with edit right can execute arbitrary database select and access da…

Fix: 13.10.11 / 14.4.7+
Fix from $1,600 2023-03-02
Commons CRITICAL 9.9
CVE-2023-26055

XWiki Commons are technical libraries common to several other top level XWiki projects. Starting in version 3.1-milestone-1, any user can edit their …

Fix: 13.10.9 / 14.4.4+
Fix from $2,300 2023-03-02
Xwiki MEDIUM 5.4
CVE-2023-26056

XWiki Platform is a generic wiki platform. Starting in version 3.0-milestone-1, it's possible to execute a script with the right of another user, pro…

Fix: 13.10.10 / 14.4.5+
Fix from $1,600 2023-03-02
Xwiki MEDIUM 6.5
CVE-2023-26479

XWiki Platform is a generic wiki platform. Starting in version 6.0, users with write rights can insert well-formed content that is not handled well b…

Fix: 13.10.10 / 14.4.6+
Fix from $1,600 2023-03-02
Xwiki MEDIUM 5.4
CVE-2023-26480

XWiki Platform is a generic wiki platform. Starting in version 12.10, a user without script rights can introduce a stored cross-site scripting by usi…

Fix: 13.10.10 / 14.4.7+
Fix from $1,600 2023-03-02
Xwiki CRITICAL 9.8
CVE-2023-26477EPSS 75%

XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, P…

Fix: 13.10.10 / 14.4.6+
Fix from $2,300 2023-03-02
Xwiki HIGH 8.1
CVE-2023-26478

XWiki Platform is a generic wiki platform. Starting in version 14.3-rc-1, `org.xwiki.store.script.TemporaryAttachmentsScriptService#uploadTemporaryAt…

Fix: 14.4.6 / 14.9+
Fix from $1,950 2023-03-02
Ckeditor Integration HIGH 8.8
CVE-2023-22457EPSS 19%

CKEditor Integration UI adds support for editing wiki pages using CKEditor. Prior to versions 1.64.3,t he `CKEditor.HTMLConverter` document lacked a …

Fix: 1.64.3+
Fix from $1,950 2023-01-04
Xwiki MEDIUM 6.5
CVE-2022-41933

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When the `reset a forgotten password` featur…

Fix: 13.10.8 / 14.4.3+
Fix from $1,600 2022-11-23
Xwiki MEDIUM 5.3
CVE-2022-41932

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to make XWiki create many new …

Fix: 13.10.8 / 14.4.2+
Fix from $1,600 2022-11-23
Xwiki HIGH 8.8
CVE-2022-41931

xwiki-platform-icon-ui is vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection'). Any user with view ri…

Fix: 13.10.7 / 14.4.2+
Fix from $1,950 2022-11-23
Xwiki HIGH 8.8
CVE-2022-41934

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on commonly access…

Fix: 13.10.8 / 14.4.3+
Fix from $1,950 2022-11-23
Xwiki HIGH 8.8
CVE-2022-41928

XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in AttachmentSelector.xml. The is…

Fix: 13.10.7 / 14.4.2+
Fix from $1,950 2022-11-23
Xwiki HIGH 8.2
CVE-2022-41930

org.xwiki.platform:xwiki-platform-user-profile-ui is missing authorization to enable or disable users. Any user (logged in or not) with access to the…

Fix: 13.10.7 / 14.4.2+
Fix from $1,950 2022-11-23
Xwiki HIGH 7.4
CVE-2022-41927

XWiki Platform is vulnerable to Cross-Site Request Forgery (CSRF) that may allow attackers to delete or rename tags without needing any confirmation.…

Fix: 13.10.7+
Fix from $1,950 2022-11-23
Xwiki HIGH 8.1
CVE-2022-41937

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application allows anyone with view acce…

Fix: 13.10.8 / 14.4.3+
Fix from $1,950 2022-11-22
Xwiki HIGH 7.5
CVE-2022-41936

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The `modifications` rest endpoint does not f…

Fix: 13.10.8 / 14.4.3+
Fix from $1,950 2022-11-22
Openid Connect HIGH 7.5
CVE-2022-39387

XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Prior to version 1.29.1, even if a wiki has an OpenID provider configure…

Fix: 1.29.1+
Fix from $1,950 2022-11-04