Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2023-29206
XWiki Commons are technical libraries common to several other top level XWiki projects. There was no check in the author of a JavaScript xobject or S…
Xwiki
after 14.8
MEDIUM 5.3
CVE-2023-29203
XWiki Commons are technical libraries common to several other top level XWiki projects. It's possible to list some users who are normally not viewabl…
Xwiki
13.10.8 / 14.4.3+
CRITICAL 9.0
CVE-2023-29201
XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduce…
Xwiki
after 14.5
CRITICAL 9.0
CVE-2023-29202
XWiki Commons are technical libraries common to several other top level XWiki projects. The RSS macro that is bundled in XWiki included the content o…
Xwiki
after 14.5
CRITICAL 9.9
CVE-2023-27479
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with view righ…
Xwiki
13.10.11 / 14.4.7+
HIGH 7.7
CVE-2023-27480
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit righ…
Xwiki
13.10.11 / 14.4.7+
HIGH 8.8
CVE-2023-26471
XWiki Platform is a generic wiki platform. Starting in version 11.6-rc-1, comments are supposed to be executed with the right of superadmin but in re…
Xwiki
13.10.10 / 14.4.6+
HIGH 8.8
CVE-2023-26472
XWiki Platform is a generic wiki platform. Starting in version 6.2-milestone-1, one can execute any wiki content with the right of IconThemeSheet aut…
Xwiki
13.10.10 / 14.4.6+
HIGH 8.8
CVE-2023-26474
XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing document content author to execut…
Xwiki
13.10.11 / 14.4.7+
HIGH 8.8
CVE-2023-26475EPSS 64%
XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted…
Xwiki
13.10.11 / 14.4.7+
HIGH 7.5
CVE-2023-26470
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to make the farm unusable by a…
Xwiki
14.0+
HIGH 7.5
CVE-2023-26476
XWiki Platform is a generic wiki platform. Starting in version 3.2-m3, users can deduce the content of the password fields by repeated call to `LiveT…
Xwiki
13.4.4 / 13.10.9+
MEDIUM 6.5
CVE-2023-26473
XWiki Platform is a generic wiki platform. Starting in version 1.3-rc-1, any user with edit right can execute arbitrary database select and access da…
Xwiki
13.10.11 / 14.4.7+
CRITICAL 9.9
CVE-2023-26055
XWiki Commons are technical libraries common to several other top level XWiki projects. Starting in version 3.1-milestone-1, any user can edit their …
Commons
13.10.9 / 14.4.4+
MEDIUM 5.4
CVE-2023-26056
XWiki Platform is a generic wiki platform. Starting in version 3.0-milestone-1, it's possible to execute a script with the right of another user, pro…
Xwiki
13.10.10 / 14.4.5+
MEDIUM 6.5
CVE-2023-26479
XWiki Platform is a generic wiki platform. Starting in version 6.0, users with write rights can insert well-formed content that is not handled well b…
Xwiki
13.10.10 / 14.4.6+
MEDIUM 5.4
CVE-2023-26480
XWiki Platform is a generic wiki platform. Starting in version 12.10, a user without script rights can introduce a stored cross-site scripting by usi…
Xwiki
13.10.10 / 14.4.7+
CRITICAL 9.8
CVE-2023-26477EPSS 75%
XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, P…
Xwiki
13.10.10 / 14.4.6+
HIGH 8.1
CVE-2023-26478
XWiki Platform is a generic wiki platform. Starting in version 14.3-rc-1, `org.xwiki.store.script.TemporaryAttachmentsScriptService#uploadTemporaryAt…
Xwiki
14.4.6 / 14.9+
HIGH 8.8
CVE-2023-22457EPSS 19%
CKEditor Integration UI adds support for editing wiki pages using CKEditor. Prior to versions 1.64.3,t he `CKEditor.HTMLConverter` document lacked a …
Ckeditor Integration
1.64.3+
MEDIUM 6.5
CVE-2022-41933
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When the `reset a forgotten password` featur…
Xwiki
13.10.8 / 14.4.3+
MEDIUM 5.3
CVE-2022-41932
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to make XWiki create many new …
Xwiki
13.10.8 / 14.4.2+
HIGH 8.8
CVE-2022-41931
xwiki-platform-icon-ui is vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection'). Any user with view ri…
Xwiki
13.10.7 / 14.4.2+
HIGH 8.8
CVE-2022-41934
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on commonly access…
Xwiki
13.10.8 / 14.4.3+
HIGH 8.8
CVE-2022-41928
XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in AttachmentSelector.xml. The is…
Xwiki
13.10.7 / 14.4.2+
HIGH 8.2
CVE-2022-41930
org.xwiki.platform:xwiki-platform-user-profile-ui is missing authorization to enable or disable users. Any user (logged in or not) with access to the…
Xwiki
13.10.7 / 14.4.2+
HIGH 7.4
CVE-2022-41927
XWiki Platform is vulnerable to Cross-Site Request Forgery (CSRF) that may allow attackers to delete or rename tags without needing any confirmation.…
Xwiki
13.10.7+
HIGH 8.1
CVE-2022-41937
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The application allows anyone with view acce…
Xwiki
13.10.8 / 14.4.3+
HIGH 7.5
CVE-2022-41936
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The `modifications` rest endpoint does not f…
Xwiki
13.10.8 / 14.4.3+
HIGH 7.5
CVE-2022-39387
XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Prior to version 1.29.1, even if a wiki has an OpenID provider configure…
Openid Connect
1.29.1+