Vulnerabilidades en xwiki

250 resultados
Análisis Vexday

O XWiki acumula 245 CVEs catalogadas, das quais 121 são classificadas como severidade crítica — concentração expressiva que merece atenção contínua de equipes de gestão de vulnerabilidades. A taxa de exploração ativa está em linha com a média geral do catálogo, mas o CVE-2025-24893 se destaca com EPSS de 0,999, indicando probabilidade máxima de exploração ativa segundo os modelos preditivos, e já figura no catálogo KEV da CISA. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que costuma refletir gaps estruturais no tratamento de entrada e saída de dados na plataforma. Com 9 CVEs com PoC pública e 5 surgidas nos últimos 90 dias, o ritmo de descoberta recente reforça a necessidade de monitoramento contínuo e aplicação prioritária de patches.

CVE-2023-29521HIGHCode injection from account/view through VFS Tree macro in xwiki-platformEPSS 1.1%CVE-2022-23619MEDIUMInformation exposure in xwiki-platformEPSS 1.1%CVE-2021-29459CRITICALXSS Cross Site ScriptingEPSS 1.1%CVE-2023-26472CRITICALXWiki Platform vulnerable to privilege escalation via async macro and IconThemeSheet from the user profileEPSS 1.1%CVE-2023-29527CRITICALCode injection from account through AWM view sheet in xwiki platformEPSS 1.1%CVE-2023-26479MEDIUMorg.xwiki.platform:xwiki-platform-rendering-parser vulnerable to Improper Handling of Exceptional ConditionsEPSS 1.1%CVE-2023-40573CRITICALXWiki Platform's Groovy jobs check the wrong author, allowing remote code executionEPSS 1.1%CVE-2023-37913CRITICALorg.xwiki.platform:xwiki-platform-office-importer vulnerable to arbitrary server side file writing from account through office converterEPSS 1.1%CVE-2024-55879CRITICALXWiki allows RCE from script right in configurable sectionsEPSS 1.1%CVE-2025-46554MEDIUMXWiki missing authorization when accessing the wiki level attachments list and metadata via REST APIEPSS 1.1%CVE-2023-40177CRITICALXWiki Platform privilege escalation (PR) from account through AWM content fieldsEPSS 1.1%CVE-2023-37908CRITICALorg.xwiki.rendering:xwiki-rendering-xml Improper Neutralization of Invalid Characters in Identifiers in Web Pages vulnerabilityEPSS 1.1%CVE-2024-37901CRITICALXWiki Platform vulnerable to remote code execution from account via SearchSuggestConfigSheetEPSS 1.1%CVE-2022-36092HIGHXWiki Platform Old Core vulnerable to Authentication Bypass Using the Login ActionEPSS 1.1%CVE-2022-29253LOWPath Traversal in XWiki PlatformEPSS 1.1%CVE-2023-30537CRITICALorg.xwiki.platform:xwiki-platform-flamingo-theme-ui vulnerable to privilege escalationEPSS 1.0%CVE-2023-29511CRITICALxwiki-platform-administration-ui vulnerable to privilege escalationEPSS 1.0%CVE-2023-36471CRITICALHTML sanitizer allows form elements in restricted in org.xwiki.commons:xwiki-commons-xmlEPSS 1.0%CVE-2025-66474HIGHXWiki vulnerable to remote code execution through insufficient protection against {{/html}} injectionEPSS 1.0%CVE-2023-35152CRITICALXWiki Platform vulnerable to privilege escalation (PR) from account through like LiveTableResultsEPSS 1.0%