Exposure of XWiki

Wikis
324
exposure score
32
sites use
1
exploited
122
critical
Vexday analysis

Com 245 CVEs catalogadas, o XWiki apresenta um volume expressivo de vulnerabilidades, sendo 121 delas de severidade crítica — número que por si só justifica atenção redobrada em ambientes que utilizam a plataforma. A falha mais comum é CWE-79 (Cross-Site Scripting), padrão que, em wikis colaborativos com renderização de conteúdo rico, tende a ter superfície de ataque ampla e impacto relevante sobre usuários autenticados. A CVE mais perigosa atualmente ativa é CVE-2025-24893, com score EPSS de 0,999 — valor que indica probabilidade extremamente alta de exploração ativa —, exigindo priorização imediata de remediação. A taxa de exploração confirmada no CISA KEV está em linha com a média geral do catálogo, mas o EPSS elevado dessa CVE sugere que a exposição real pode ser significativamente maior do que o número de entradas KEV indica.

CVEs

250 results
CVE-2025-49586HIGHXWiki allows remote code execution through preview of XClass changes in AWM editorEPSS 0.7%CVE-2023-27480HIGHData leak through a XAR import XXE attack in xwiki-platform-xar-modelEPSS 0.7%CVE-2023-35153CRITICALXWiki Platform vulnerable to stored cross-site scripting in ClassEditSheet page via name parametersEPSS 0.7%CVE-2024-55663HIGHXWiki Platform has an SQL injection in getdocuments.vm with sort parameterEPSS 0.7%CVE-2022-41929MEDIUMMissing Authorization in User#setDisabledStatus in org.xwiki.platform:xwiki-platform-oldcoreEPSS 0.7%CVE-2023-35151HIGHXWiki Platform may show email addresses in clear in REST resultsEPSS 0.7%CVE-2023-34464CRITICALXWiki vulnerable to stored cross-site scripting via any wiki document and the displaycontent/rendercontent templateEPSS 0.7%CVE-2023-48240CRITICALXWiki Platform sends cookies to external images in rendered diff and is vulnerable to server side request forgeryEPSS 0.7%CVE-2024-31988CRITICALXWiki Platform CSRF remote code execution through the realtime HTML Converter APIEPSS 0.7%CVE-2024-37899CRITICALDisabling a user account changes its author, allowing RCE from user account in XWikiEPSS 0.7%CVE-2023-29203LOWUnauthenticated user can have information about hidden users on subwikis through uorgsuggest.vm EPSS 0.7%CVE-2022-23615MEDIUMPartial authorization bypass on document save in xwiki-platformEPSS 0.7%CVE-2024-43401CRITICALIn XWiki Platform, payloads stored in content is executed when a user with script/programming right edit themEPSS 0.7%CVE-2023-29513MEDIUMUsers can be created even when registration is disabled without validation via the template macro in xwiki-platformEPSS 0.7%CVE-2023-26480HIGHXWiki-Platform vulnerable to stored Cross-site Scripting via the HTML displayer in Live DataEPSS 0.7%CVE-2023-26478MEDIUMorg.xwiki.platform:xwiki-platform-store-filesystem-oldcore has Exposed Dangerous Method or FunctionEPSS 0.7%CVE-2023-37277CRITICALXWiki Platform vulnerable to cross-site request forgery (CSRF) via the REST APIEPSS 0.7%CVE-2023-50722CRITICALXWiki Platform XSS/CSRF Remote Code Execution in XWiki.ConfigurableClassEPSS 0.7%CVE-2023-32070CRITICALImproper Neutralization of Script in Attributes in XWiki (X)HTML renderersEPSS 0.7%CVE-2025-53837CRITICALorg.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issueEPSS 0.6%