Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.7
CVE-2021-32730
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A cross-site request forgery vulnerability e…
Xwiki
12.10.5+
MEDIUM 5.4
CVE-2021-32729
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A vulnerability exists in versions prior to …
Xwiki
12.6.8 / 12.10.4+
HIGH 8.8
CVE-2021-32620
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 11.10.13, 12.6.7, and 1…
Xwiki
11.10.13 / 12.6.7+
HIGH 8.8
CVE-2021-32621
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 12.6.7 and 12.10.3, a u…
Xwiki
12.6.7 / 12.10.3+
MEDIUM 6.1
CVE-2021-29459
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible to persistently inject script…
Xwiki
12.6.3 / 12.8+
HIGH 8.8
CVE-2021-21380
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of XWiki Platform (and …
Xwiki
after 12.8
MEDIUM 5.4
CVE-2021-21379
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of XWiki Platform, the …
Xwiki
11.10.11 / 12.6.3+
MEDIUM 5.4
CVE-2021-3137
XWiki 12.10.2 allows XSS via an SVG document to the upload feature of the comment section.
Xwiki
No fix yet
HIGH 7.5
CVE-2020-13654
XWiki Platform before 12.8 mishandles escaping in the property displayer.
Xwiki
12.8+
HIGH 8.8
CVE-2020-15252
In XWiki before version 12.5 and 11.10.6, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet …
Xwiki
11.10.6 / 12.5+
MEDIUM 6.6
CVE-2020-15171
In XWiki before versions 11.10.5 or 12.2.1, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servle…
Xwiki
11.10.5 / 12.2.1+
HIGH 8.8
CVE-2020-11057
In XWiki Platform 7.2 through 11.10.2, registered users without scripting/programming permissions are able to execute python/groovy scripts while edi…
Xwiki
after 11.10.2
MEDIUM 6.5
CVE-2019-15302
The pad management logic in XWiki labs CryptPad before 3.0.0 allows a remote attacker (who has access to a Rich Text pad with editing rights for the …
Cryptpad
3.0.0+
MEDIUM 5.4
CVE-2018-16277
The Image Import function in XWiki through 10.7 has XSS.
Xwiki
after 10.7
MEDIUM 6.1
CVE-2017-1000051
Cross-site scripting (XSS) vulnerability in pad export in XWiki labs CryptPad before 1.1.1 allows remote attackers to inject arbitrary web script or …
Cryptpad
after 1.1.0
HIGH 7.5
CVE-2010-4641
SQL injection vulnerability in XWiki Enterprise before 2.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Xwiki
after 2.4
MEDIUM 6.5
CVE-2006-7223
PreviewAction in XWiki 0.9.543 through 0.9.1252 does not set the Author field to the identity of the user who last modified a document, which allows …
Xwiki
Mitigation only
MEDIUM 5.0
CVE-2005-4862
The search functionality in XWiki 0.9.793 indexes cleartext user passwords, which allows remote attackers to obtain sensitive information via a searc…
Xwiki
Mitigation only