Exposición de XWiki

Wikis
324
score de exposición
32
sitios usan
1
en explotación
122
críticos
Análisis Vexday

Com 245 CVEs catalogadas, o XWiki apresenta um volume expressivo de vulnerabilidades, sendo 121 delas de severidade crítica — número que por si só justifica atenção redobrada em ambientes que utilizam a plataforma. A falha mais comum é CWE-79 (Cross-Site Scripting), padrão que, em wikis colaborativos com renderização de conteúdo rico, tende a ter superfície de ataque ampla e impacto relevante sobre usuários autenticados. A CVE mais perigosa atualmente ativa é CVE-2025-24893, com score EPSS de 0,999 — valor que indica probabilidade extremamente alta de exploração ativa —, exigindo priorização imediata de remediação. A taxa de exploração confirmada no CISA KEV está em linha com a média geral do catálogo, mas o EPSS elevado dessa CVE sugere que a exposição real pode ser significativamente maior do que o número de entradas KEV indica.

CVEs

250 resultados
CVE-2025-49582HIGHXWiki's required right warnings for macros are incompleteEPSS 0.9%CVE-2021-43841MEDIUMXSS by SVG upload in xwiki-platformEPSS 0.9%CVE-2022-36093HIGHXWiki Platform Web Templates vulnerable to Unauthorized User Registration Through the Distribution WizardEPSS 0.9%CVE-2023-26470MEDIUMIn XWiki Platform, saving a document with a large object number leads to persistent OOM errorsEPSS 0.9%CVE-2023-34465CRITICALXWiki Platform's Mail.MailConfig can be edited by any user with edit rightsEPSS 0.9%CVE-2022-41930HIGHorg.xwiki.platform:xwiki-platform-user-profile-ui missing authorization to enable or disable usersEPSS 0.8%CVE-2023-38509MEDIUMXWiki Platform's obfuscated email addresses should not be sortedEPSS 0.8%CVE-2023-31126CRITICALImproper Neutralization of Invalid Characters in Data Attribute Names in org.xwiki.commons:xwiki-commons-xmlEPSS 0.8%CVE-2022-36091HIGHXWiki Platform Web Templates vulnerable to Missing Authorization and Exposure of Private Personal Information to an Unauthorized ActorEPSS 0.8%CVE-2022-24821MEDIUMIncorrect Use of Privileged APIs in org.xwiki.platform.skin.skinxEPSS 0.8%CVE-2022-31167HIGHXWiki Platform Security Parent POM vulnerable to overwriting of security rules of a page with a final page having the same referenceEPSS 0.8%CVE-2022-23618MEDIUMOpen Redirect in xwiki-platformEPSS 0.8%CVE-2022-41937CRITICALMissing Authorization in XWiki PlatformEPSS 0.8%CVE-2022-41935MEDIUMExposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-livetable-uiEPSS 0.8%CVE-2023-46244CRITICALPrivilege escalation in Xwiki platformEPSS 0.8%CVE-2023-26474CRITICALXWiki Platform vulnerable to privilege escalation via properties with wiki syntax that are executed with wrong authorEPSS 0.8%CVE-2024-55662CRITICALXWiki allows remote code execution through the extension sheetEPSS 0.8%CVE-2022-41936MEDIUMExposure of Private Personal Information to an Unauthorized Actor in xwiki-platform-rest-serverEPSS 0.8%CVE-2023-32069CRITICALXWiki Platform privilege escalation (PR)/RCE from account through class sheetEPSS 0.8%CVE-2023-37911MEDIUMorg.xwiki.platform:xwiki-platform-oldcore may leak data through deleted and re-created documentsEPSS 0.8%