Vulnerability index

Browse CVEs

258 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xwiki MEDIUM 5.7
CVE-2021-32730

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A cross-site request forgery vulnerability e…

Fix: 12.10.5+
Fix from $1,600 2021-07-01
Xwiki MEDIUM 5.4
CVE-2021-32729

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A vulnerability exists in versions prior to …

Fix: 12.6.8 / 12.10.4+
Fix from $1,600 2021-07-01
Xwiki HIGH 8.8
CVE-2021-32620

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 11.10.13, 12.6.7, and 1…

Fix: 11.10.13 / 12.6.7+
Fix from $1,950 2021-05-28
Xwiki HIGH 8.8
CVE-2021-32621

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 12.6.7 and 12.10.3, a u…

Fix: 12.6.7 / 12.10.3+
Fix from $1,950 2021-05-28
Xwiki MEDIUM 6.1
CVE-2021-29459

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible to persistently inject script…

Fix: 12.6.3 / 12.8+
Fix from $1,600 2021-04-20
Xwiki HIGH 8.8
CVE-2021-21380

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of XWiki Platform (and …

Fix: after 12.8
Fix from $1,950 2021-03-23
Xwiki MEDIUM 5.4
CVE-2021-21379

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of XWiki Platform, the …

Fix: 11.10.11 / 12.6.3+
Fix from $1,600 2021-03-12
Xwiki MEDIUM 5.4
CVE-2021-3137

XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.

No fix yet
Fix from $1,600 2021-01-20
Xwiki HIGH 7.5
CVE-2020-13654

XWiki Platform before 12.8 mishandles escaping in the property displayer.

Fix: 12.8+
Fix from $1,950 2020-12-31
Xwiki HIGH 8.8
CVE-2020-15252

In XWiki before version 12.5 and 11.10.6, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet …

Fix: 11.10.6 / 12.5+
Fix from $1,950 2020-10-16
Xwiki MEDIUM 6.6
CVE-2020-15171

In XWiki before versions 11.10.5 or 12.2.1, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servle…

Fix: 11.10.5 / 12.2.1+
Fix from $1,600 2020-09-10
Xwiki HIGH 8.8
CVE-2020-11057

In XWiki Platform 7.2 through 11.10.2, registered users without scripting/programming permissions are able to execute python/groovy scripts while edi…

Fix: after 11.10.2
Fix from $1,950 2020-05-12
Cryptpad MEDIUM 6.5
CVE-2019-15302

The pad management logic in XWiki labs CryptPad before 3.0.0 allows a remote attacker (who has access to a Rich Text pad with editing rights for the …

Fix: 3.0.0+
Fix from $1,600 2019-09-11
Xwiki MEDIUM 5.4
CVE-2018-16277

The Image Import function in XWiki through 10.7 has XSS.

Fix: after 10.7
Fix from $1,600 2018-09-28
Cryptpad MEDIUM 6.1
CVE-2017-1000051

Cross-site scripting (XSS) vulnerability in pad export in XWiki labs CryptPad before 1.1.1 allows remote attackers to inject arbitrary web script or …

Fix: after 1.1.0
Fix from $1,600 2017-07-17
Xwiki HIGH 7.5
CVE-2010-4641

SQL injection vulnerability in XWiki Enterprise before 2.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Fix: after 2.4
Fix from $1,950 2010-12-30
Xwiki MEDIUM 6.5
CVE-2006-7223

PreviewAction in XWiki 0.9.543 through 0.9.1252 does not set the Author field to the identity of the user who last modified a document, which allows …

Mitigation only
Fix from $1,600 2007-09-14
Xwiki MEDIUM 5.0
CVE-2005-4862

The search functionality in XWiki 0.9.793 indexes cleartext user passwords, which allows remote attackers to obtain sensitive information via a searc…

Mitigation only
Fix from $1,600 2005-12-31