Exposición de XWiki

Wikis
324
score de exposición
32
sitios usan
1
en explotación
122
críticos
Análisis Vexday

Com 245 CVEs catalogadas, o XWiki apresenta um volume expressivo de vulnerabilidades, sendo 121 delas de severidade crítica — número que por si só justifica atenção redobrada em ambientes que utilizam a plataforma. A falha mais comum é CWE-79 (Cross-Site Scripting), padrão que, em wikis colaborativos com renderização de conteúdo rico, tende a ter superfície de ataque ampla e impacto relevante sobre usuários autenticados. A CVE mais perigosa atualmente ativa é CVE-2025-24893, com score EPSS de 0,999 — valor que indica probabilidade extremamente alta de exploração ativa —, exigindo priorização imediata de remediação. A taxa de exploração confirmada no CISA KEV está em linha com a média geral do catálogo, mas o EPSS elevado dessa CVE sugere que a exposição real pode ser significativamente maior do que o número de entradas KEV indica.

CVEs

250 resultados
CVE-2023-26473MEDIUMXWiki Platform allows unprivileged users to make arbitrary select queries using DatabaseListProperty and suggest.vmEPSS 0.6%CVE-2024-21651HIGHXWiki Denial of Service attack through attachmentsEPSS 0.6%CVE-2023-35157HIGHXWiki Platform vulnerable to reflected cross-site scripting via delattachment actionEPSS 0.6%CVE-2025-32430MEDIUMXWiki Platform contains Reflected XSS vulnerability in two templatesEPSS 0.6%CVE-2023-45137CRITICALXWiki Platform XSS with edit right in the create document form for existing pagesEPSS 0.6%CVE-2023-40572CRITICALXWiki Platform vulnerable to CSRF privilege escalation/RCE via the create actionEPSS 0.6%CVE-2021-32730MEDIUMNo CSRF protection on the password change formEPSS 0.6%CVE-2026-33137CRITICALXWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName}EPSS 0.6%CVE-2025-49581HIGHXWiki allows remote code execution through default value of wiki macro wiki-type parametersEPSS 0.6%CVE-2023-29205CRITICALorg.xwiki.platform:xwiki-platform-rendering-xwiki vulnerable to stored cross-site scripting via HTML and raw macroEPSS 0.6%CVE-2024-55876MEDIUMXWiki's scheduler in subwiki allows scheduling operations for any main wiki userEPSS 0.6%CVE-2025-32970MEDIUMorg.xwiki.platform:xwiki-platform-wysiwyg-api Open Redirect vulnerabilityEPSS 0.6%CVE-2025-54385HIGHXWiki Platform's searchDocuments API allows for SQL injectionEPSS 0.6%CVE-2023-37910HIGHorg.xwiki.platform:xwiki-platform-attachment-api vulnerable to Missing Authorization on Attachment MoveEPSS 0.6%CVE-2025-32968HIGHorg.xwiki.platform:xwiki-platform-oldcore allows SQL injection in short form select requests through the script query APIEPSS 0.6%CVE-2023-29515HIGHCross-site scripting (XSS) in xwiki-platformEPSS 0.6%CVE-2025-29926HIGHThe WikiManager REST API allows any user to create wikisEPSS 0.6%CVE-2025-53836CRITICALXWiki Rendering is vulnerable to RCE attacks when processing nested macrosEPSS 0.6%CVE-2026-24128MEDIUMXWiki Affected by Reflected Cross-Site Scripting (XSS) in Error MessagesEPSS 0.6%CVE-2023-26056MEDIUMXWiki Platform allows macro execution as any user without programming rights through the context macroEPSS 0.6%