cbcvebase.

Xwiki Xwiki-Platform vulnerabilities

231 known vulnerabilities affecting xwiki/xwiki-platform.

Total CVEs
231
CISA KEV
1
actively exploited
Public exploits
36
Exploited in wild
15
Severity breakdown
CRITICAL29HIGH114MEDIUM85LOW3

Vulnerabilities

Page 9 of 12
CVE-2023-35151P3HIGHCVSS 7.5v>= 7.3-milestone-1, < 14.4.8v>= 14.5, < 14.10.6+1 more2023-06-23
CVE-2023-35151 [HIGH] CWE-359 CVE-2023-35151: XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obfuscated passwords, even when the mail obfuscation is activated. The issue has been patched in XWiki 14.4.8, 14.10.6, and 15.1. There is no known workaround.
nvd
CVE-2024-43401P3HIGHCVSS 8.0fixed in 15.10-rc-12024-08-19
CVE-2024-43401 [HIGH] CWE-269 CVE-2024-43401: XWiki Platform is a generic wiki platform offering runtime services for applications built on top of XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIWYG editor. The user with elevated rights is not warned beforehand that they are going to edit possibly dangerous c
nvd
CVE-2025-49587P3HIGHCVSS 8.0v>= 15.9-rc-1, < 15.10.16v>= 16.0.0-rc-1, < 16.4.7+1 more2025-06-13
CVE-2025-49587 [HIGH] CWE-357 CVE-2025-49587: XWiki is an open-source wiki software platform. When a user without script right creates a document XWiki is an open-source wiki software platform. When a user without script right creates a document with an XWiki.Notifications.Code.NotificationDisplayerClass object, and later an admin edits and saves that document, the possibly malicious content of that object is output as raw HTML, allowing XSS attacks. While the notification displayer executes Vel
nvd
CVE-2022-41936P3HIGHCVSS 7.5v>= 8.1, < 13.10.8v>= 14.0.0, < 14.4.3+1 more2022-11-22
CVE-2022-41936 [HIGH] CWE-359 CVE-2022-41936: XWiki Platform is a generic wiki platform offering runtime services for applications built on top of XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The `modifications` rest endpoint does not filter out entries according to the user's rights. Therefore, information hidden from unauthorized users are exposed though the `modifications` rest endpoint (comments and page names etc). Users should upg
nvd
CVE-2026-48047P3MEDIUMCVSS 5.9v>= 9.6-rc-1, < 16.10.17v>= 17.0.0-rc-1, < 17.4.9+1 more2026-08-07
CVE-2026-48047 [MEDIUM] CWE-24 CVE-2026-48047: XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9. XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to versions 16.10.17, 17.4.9, and 17.10.3, a potential path traversal vulnerability allow an attacker who manages to get a malicious WebJar extension installed on the wiki to write arbitrary files. While the consequences could be sever
nvd
CVE-2023-29208P3HIGHCVSS 7.5v>= 1.2-milestone-1, < 13.10.11v>= 14.0-rc-1, < 14.4.7+1 more2023-04-15
CVE-2023-29208 [HIGH] CWE-668 CVE-2023-29208: XWiki Commons are technical libraries common to several other top level XWiki projects. Rights added XWiki Commons are technical libraries common to several other top level XWiki projects. Rights added to a document are not taken into account for viewing it once it's deleted. Note that this vulnerability only impact deleted documents that where containing view rights: the view rights provided on a space of a deleted document are properly checked. The
nvd
CVE-2023-29507P3HIGHCVSS 7.2v>= 14.5, < 14.10v>= 14.4.1, < 14.4.72023-04-16
CVE-2023-29507 [HIGH] CWE-648 CVE-2023-29507: XWiki Commons are technical libraries common to several other top level XWiki projects. The Document XWiki Commons are technical libraries common to several other top level XWiki projects. The Document script API returns directly a DocumentAuthors allowing to set any authors to the document, which in consequence can allow subsequent executions of scripts since this author is used for checking rights. The problem has been patched in XWiki 14.10 and 14
nvd
CVE-2023-26473P3MEDIUMCVSS 6.5v>= 1.3-rc-1, < 13.10.11v>= 14.0, < 14.4.7+1 more2023-03-02
CVE-2023-26473 [MEDIUM] CWE-284 CVE-2023-26473: XWiki Platform is a generic wiki platform. Starting in version 1.3-rc-1, any user with edit right ca XWiki Platform is a generic wiki platform. Starting in version 1.3-rc-1, any user with edit right can execute arbitrary database select and access data stored in the database. The problem has been patched in XWiki 13.10.11, 14.4.7, and 14.10. There is no workaround for this vulnerability other than upgrading.
nvd
CVE-2023-41046P3MEDIUMCVSS 6.3v>= 7.2, < 14.10.10v>= 15.0-rc-1, < 15.4-rc-12023-09-01
CVE-2023-41046 [MEDIUM] CWE-862 CVE-2023-41046: XWiki Platform is a generic wiki platform offering runtime services for applications built on top of XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible in XWiki to execute Velocity code without having script right by creating an XClass with a property of type "TextArea" and content type "VelocityCode" or "VelocityWiki". For the former, the syntax of the document needs to be set th
nvd
CVE-2025-54124P3MEDIUMCVSS 6.5v>= 9.8-rc-1, < 16.4.7v>= 16.5.0-rc-1, < 16.10.5+1 more2025-08-06
CVE-2025-54124 [MEDIUM] CWE-359 CVE-2025-54124: XWiki Platform is a generic wiki platform offering runtime services for applications built on top of XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 9.8-rc-1 through 16.4.6, 16.5.0-rc-1 through 16.10.4, and 17.0.0-rc-1 through 17.1.0, any user with editing rights can create an XClass with a database list property that referen
nvd
CVE-2023-37911P3MEDIUMCVSS 6.5v>= 9.4-rc-1, < 14.10.8v>= 15.0-rc-1, < 15.3-rc-12023-10-25
CVE-2023-37911 [MEDIUM] CWE-668 CVE-2023-37911: XWiki Platform is a generic wiki platform offering runtime services for applications built on top of XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 9.4-rc-1 and prior to versions 14.10.8 and 15.3-rc-1, when a document has been deleted and re-created, it is possible for users with view right on the re-created document but not on the deleted document to view the contents of
nvd
CVE-2023-26470P3HIGHCVSS 7.5fixed in 14.0-rc-12023-03-02
CVE-2023-26470 [HIGH] CWE-400 CVE-2023-26470: XWiki Platform is a generic wiki platform offering runtime services for applications built on top of XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to make the farm unusable by adding an object to a page with a huge number (e.g. 67108863). Most of the time this will fill the memory allocated to XWiki and make it unusable every time this document is manipulated. This issue has bee
nvd
CVE-2020-15171P3MEDIUMCVSS 6.6v<11.10.5v>=12.0.0, <12.2.12020-09-10
CVE-2020-15171 [MEDIUM] CWE-94 CVE-2020-15171: In XWiki before versions 11.10.5 or 12.2.1, any user with SCRIPT right (EDIT right before XWiki 7.4) In XWiki before versions 11.10.5 or 12.2.1, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet context which contains tools allowing to instantiate arbitrary Java objects and invoke methods that may lead to arbitrary code execution. The only workaround is to give SCRIPT right only to trusted use
nvd
CVE-2022-23617P3MEDIUMCVSS 6.5v>= 13.0.0, < 13.2-rc-1fixed in 12.10.62022-02-09
CVE-2022-23617 [MEDIUM] CWE-862 CVE-2022-23617: XWiki Platform is a generic wiki platform offering runtime services for applications built on top of XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit right can copy the content of a page it does not have access to by using it as template of a new page. This issue has been patched in XWiki 13.2CR1 and 12.10.6. Users are advised to update. There are no kno
nvd
CVE-2023-29520P3MEDIUMCVSS 6.5fixed in 13.10.11v>= 14.0.0, < 14.4.8+1 more2023-04-19
CVE-2023-29520 [MEDIUM] CWE-248 CVE-2023-29520: XWiki Platform is a generic wiki platform offering runtime services for applications built on top of XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to break many translations coming from wiki pages by creating a corrupted document containing a translation object. This will lead to a broken page. The vulnerability has been patched in XWiki 15.0-rc-1, 14.10.1, 14.4.8, and 13.10.1
nvd
CVE-2024-46978P3MEDIUMCVSS 6.5v>= 13.2-rc-1, < 14.10.21v>= 15.0.0, < 15.5.5+1 more2024-09-18
CVE-2024-46978 [MEDIUM] CWE-648 CVE-2024-46978: XWiki Platform is a generic wiki platform offering runtime services for applications built on top of XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible for any user knowing the ID of a notification filter preference of another user, to enable/disable it or even delete it. The impact is that the target user might start loosing notifications on some pages because of this. This vulner
nvd
CVE-2022-31167P3MEDIUMCVSS 6.5v>= 5.0, < 12.10.11v>= 13.0, < 13.4.6+1 more2022-09-07
CVE-2022-31167 [MEDIUM] CWE-285 CVE-2022-31167: XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki pla XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform. Starting with version 5.0 and prior to 12.10.11, 13.10.1, and 13.4.6, a bug in the security cache stores rules associated to document Page1.Page2 and space Page1.Page2 in the same cache entry. That means that it's possible to overwrite the righ
nvd
CVE-2023-50732P3MEDIUMCVSS 6.3v>= 8.3-rc-1, < 14.10.7v>= 15.0-rc-1, < 15.2-rc-12023-12-21
CVE-2023-50732 [MEDIUM] CWE-863 CVE-2023-50732: XWiki Platform is a generic wiki platform offering runtime services for applications built on top of XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute a Velocity script without script right through the document tree. This has been patched in XWiki 14.10.7 and 15.2RC1.
nvd
CVE-2024-37900P4MEDIUMCVSS 4.6v>= 4.2-milestone-3, < 14.10.21v>= 15.0-rc-1, < 15.5.5+2 more2024-07-31
CVE-2024-37900 [MEDIUM] CWE-96 CVE-2024-37900: XWiki Platform is a generic wiki platform offering runtime services for applications built on top of XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When uploading an attachment with a malicious filename, malicious JavaScript code could be executed. This requires a social engineering attack to get the victim into uploading a file with a malicious name. The malicious code is solely executed dur
nvd
CVE-2022-41927P3HIGHCVSS 7.4v>= 3.2-milestone-2, < 13.10.7v>= 14.0.0, < 14.4.12022-11-23
CVE-2022-41927 [HIGH] CWE-352 CVE-2022-41927: XWiki Platform is vulnerable to Cross-Site Request Forgery (CSRF) that may allow attackers to delete XWiki Platform is vulnerable to Cross-Site Request Forgery (CSRF) that may allow attackers to delete or rename tags without needing any confirmation. The problem has been patched in XWiki 13.10.7, 14.4.1 and 14.5RC1. Workarounds: It's possible to patch existing instances directly by editing the page Main.Tags and add this kind of check, in the code fo
nvd
Xwiki Xwiki-Platform vulnerabilities | cvebase