Exposición de XWiki

Wikis
324
score de exposición
32
sitios usan
1
en explotación
122
críticos
Análisis Vexday

Com 245 CVEs catalogadas, o XWiki apresenta um volume expressivo de vulnerabilidades, sendo 121 delas de severidade crítica — número que por si só justifica atenção redobrada em ambientes que utilizam a plataforma. A falha mais comum é CWE-79 (Cross-Site Scripting), padrão que, em wikis colaborativos com renderização de conteúdo rico, tende a ter superfície de ataque ampla e impacto relevante sobre usuários autenticados. A CVE mais perigosa atualmente ativa é CVE-2025-24893, com score EPSS de 0,999 — valor que indica probabilidade extremamente alta de exploração ativa —, exigindo priorização imediata de remediação. A taxa de exploração confirmada no CISA KEV está em linha com a média geral do catálogo, mas o EPSS elevado dessa CVE sugere que a exposição real pode ser significativamente maior do que o número de entradas KEV indica.

CVEs

250 resultados
CVE-2023-34466MEDIUMXWiki Platform's tags on non-viewable pages can be revealed to usersEPSS 0.6%CVE-2024-46979MEDIUMData leak of notification filters of users in XWiki PlatformEPSS 0.5%CVE-2024-31986CRITICALXWiki Platform CSRF remote code execution through scheduler job's document referenceEPSS 0.5%CVE-2025-46557HIGHAny user with view access to the XWiki space can change the authenticatorEPSS 0.5%CVE-2026-40105MEDIUMXWiki has Reflected Cross-Site Scripting (XSS) in its page history compare functionalityEPSS 0.5%CVE-2023-41046MEDIUMVelocity execution without script rights in Xwiki platformEPSS 0.5%CVE-2026-34151HIGHXWiki Platform: Resource path traversal via /skin/ action endpoint in Jetty 12+EPSS 0.5%CVE-2026-33229HIGHXWiki Platform affected by remote code execution with script right through unprotected Velocity scripting APIEPSS 0.5%CVE-2022-41932HIGHCreation of new database tables through login form on PostgreSQLEPSS 0.5%CVE-2023-29520MEDIUMPage render failure due to broken translations in xwiki-platformEPSS 0.5%CVE-2024-46978MEDIUMMissing checks for notification filter preferences editions in XWiki PlatformEPSS 0.5%CVE-2024-56158CRITICALXWiki allows SQL injection in query endpoint of REST API with OracleEPSS 0.5%CVE-2024-21648HIGHXWiki has no right protection on rollback actionEPSS 0.5%CVE-2025-66472MEDIUMXWiki vulnerable to a reflected XSS via xredirect parameter in DeleteApplicationEPSS 0.5%CVE-2021-32729LOWA user without PR can reset user authentication failures informationEPSS 0.5%CVE-2024-43400CRITICALXWiki Platform allows XSS through XClass name in string propertiesEPSS 0.5%CVE-2023-50732HIGHVelocity execution without script right through tree macroEPSS 0.5%CVE-2025-32972LOWThe lesscss script service allows cache clearing without programming rightEPSS 0.5%CVE-2022-41933MEDIUMPlaintext storage of password in org.xwiki.platform:xwiki-platform-security-authentication-defaultEPSS 0.5%CVE-2021-21379HIGHIt's possible to execute anything with the rights of the author of a macro which uses the {{wikimacrocontent}} macroEPSS 0.5%