Vulnerabilidades en xwiki

250 resultados
Análisis Vexday

O XWiki acumula 245 CVEs catalogadas, das quais 121 são classificadas como severidade crítica — concentração expressiva que merece atenção contínua de equipes de gestão de vulnerabilidades. A taxa de exploração ativa está em linha com a média geral do catálogo, mas o CVE-2025-24893 se destaca com EPSS de 0,999, indicando probabilidade máxima de exploração ativa segundo os modelos preditivos, e já figura no catálogo KEV da CISA. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que costuma refletir gaps estruturais no tratamento de entrada e saída de dados na plataforma. Com 9 CVEs com PoC pública e 5 surgidas nos últimos 90 dias, o ritmo de descoberta recente reforça a necessidade de monitoramento contínuo e aplicação prioritária de patches.

CVE-2025-49580HIGHXWiki allows privilege escalation through link refactoringEPSS 0.5%CVE-2025-49584HIGHXWiki makes title of inaccessible pages available through the class property values REST APIEPSS 0.4%CVE-2023-29213CRITICALorg.xwiki.platform:xwiki-platform-logging-ui Injection vulnerabilityEPSS 0.4%CVE-2025-54124HIGHXWiki Platform: Any user with editing rights can access password properties through Database List PropertiesEPSS 0.4%CVE-2026-48047MEDIUMXWiki Platform vulnerable to potential arbitrary file writing using path traversal from (subwiki) adminEPSS 0.4%CVE-2025-49587MEDIUMXWiki does not require right warnings for notification displayer objectsEPSS 0.4%CVE-2025-49585HIGHXWiki does not require right warnings for XClass definitionsEPSS 0.4%CVE-2023-29508HIGHorg.xwiki.platform:xwiki-platform-livedata-macro vulnerable to Cross-site ScriptingEPSS 0.4%CVE-2022-36095MEDIUMXWiki Cross-Site Request Forgery (CSRF) for actions on tagsEPSS 0.4%CVE-2025-23025CRITICALPrivilege escalation (PR) through realtime WYSIWYG editing in XWikiEPSS 0.4%CVE-2022-29161MEDIUMCrypto script service uses hashing algorithm SHA1 with RSA for certificate signature in xwiki-platformEPSS 0.4%CVE-2025-66473HIGHXWiki's REST APIs don't enforce any limits, leading to unavailability and OOM in large wikisEPSS 0.4%CVE-2026-40104MEDIUMXWiki's REST APIs can list all pages/spaces, leading to unavailabilityEPSS 0.4%CVE-2024-37898MEDIUMXWiki Platform vulnerable to document deletion and overwrite from editEPSS 0.4%CVE-2025-29924HIGHXWiki uses the wrong wiki reference in AuthorizationManagerEPSS 0.4%CVE-2025-32973CRITICALorg.xwiki.platform:xwiki-platform-component-wiki provides no warning when granting XWiki.ComponentClass programming rightEPSS 0.4%CVE-2023-46242CRITICALCode injection in XWiki PlatformEPSS 0.4%CVE-2025-32971LOWXWiki Solr script service doesn't take dropped programming right into accountEPSS 0.4%CVE-2024-31464MEDIUMXWiki Platform: Password hash might be leaked by diff once the xobject holding them is deletedEPSS 0.4%CVE-2025-58049MEDIUMXWiki PDF export jobs store sensitive cookies unencrypted in job statusesEPSS 0.4%