Exposure of XWiki

Wikis
324
exposure score
32
sites use
1
exploited
122
critical
Vexday analysis

Com 245 CVEs catalogadas, o XWiki apresenta um volume expressivo de vulnerabilidades, sendo 121 delas de severidade crítica — número que por si só justifica atenção redobrada em ambientes que utilizam a plataforma. A falha mais comum é CWE-79 (Cross-Site Scripting), padrão que, em wikis colaborativos com renderização de conteúdo rico, tende a ter superfície de ataque ampla e impacto relevante sobre usuários autenticados. A CVE mais perigosa atualmente ativa é CVE-2025-24893, com score EPSS de 0,999 — valor que indica probabilidade extremamente alta de exploração ativa —, exigindo priorização imediata de remediação. A taxa de exploração confirmada no CISA KEV está em linha com a média geral do catálogo, mas o EPSS elevado dessa CVE sugere que a exposição real pode ser significativamente maior do que o número de entradas KEV indica.

CVEs

250 results
CVE-2025-49580HIGHXWiki allows privilege escalation through link refactoringEPSS 0.5%CVE-2025-49584HIGHXWiki makes title of inaccessible pages available through the class property values REST APIEPSS 0.4%CVE-2023-29213CRITICALorg.xwiki.platform:xwiki-platform-logging-ui Injection vulnerabilityEPSS 0.4%CVE-2025-54124HIGHXWiki Platform: Any user with editing rights can access password properties through Database List PropertiesEPSS 0.4%CVE-2026-48047MEDIUMXWiki Platform vulnerable to potential arbitrary file writing using path traversal from (subwiki) adminEPSS 0.4%CVE-2025-49585HIGHXWiki does not require right warnings for XClass definitionsEPSS 0.4%CVE-2025-49587MEDIUMXWiki does not require right warnings for notification displayer objectsEPSS 0.4%CVE-2023-29508HIGHorg.xwiki.platform:xwiki-platform-livedata-macro vulnerable to Cross-site ScriptingEPSS 0.4%CVE-2022-36095MEDIUMXWiki Cross-Site Request Forgery (CSRF) for actions on tagsEPSS 0.4%CVE-2025-23025CRITICALPrivilege escalation (PR) through realtime WYSIWYG editing in XWikiEPSS 0.4%CVE-2022-29161MEDIUMCrypto script service uses hashing algorithm SHA1 with RSA for certificate signature in xwiki-platformEPSS 0.4%CVE-2025-66473HIGHXWiki's REST APIs don't enforce any limits, leading to unavailability and OOM in large wikisEPSS 0.4%CVE-2026-40104MEDIUMXWiki's REST APIs can list all pages/spaces, leading to unavailabilityEPSS 0.4%CVE-2024-37898MEDIUMXWiki Platform vulnerable to document deletion and overwrite from editEPSS 0.4%CVE-2025-29924HIGHXWiki uses the wrong wiki reference in AuthorizationManagerEPSS 0.4%CVE-2025-32973CRITICALorg.xwiki.platform:xwiki-platform-component-wiki provides no warning when granting XWiki.ComponentClass programming rightEPSS 0.4%CVE-2023-46242CRITICALCode injection in XWiki PlatformEPSS 0.4%CVE-2025-32971LOWXWiki Solr script service doesn't take dropped programming right into accountEPSS 0.4%CVE-2024-31464MEDIUMXWiki Platform: Password hash might be leaked by diff once the xobject holding them is deletedEPSS 0.4%CVE-2025-58049MEDIUMXWiki PDF export jobs store sensitive cookies unencrypted in job statusesEPSS 0.4%