Vulnerabilidades en xwiki

250 resultados
Análisis Vexday

O XWiki acumula 245 CVEs catalogadas, das quais 121 são classificadas como severidade crítica — concentração expressiva que merece atenção contínua de equipes de gestão de vulnerabilidades. A taxa de exploração ativa está em linha com a média geral do catálogo, mas o CVE-2025-24893 se destaca com EPSS de 0,999, indicando probabilidade máxima de exploração ativa segundo os modelos preditivos, e já figura no catálogo KEV da CISA. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que costuma refletir gaps estruturais no tratamento de entrada e saída de dados na plataforma. Com 9 CVEs com PoC pública e 5 surgidas nos últimos 90 dias, o ritmo de descoberta recente reforça a necessidade de monitoramento contínuo e aplicação prioritária de patches.

CVE-2023-29517HIGHExposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-office-viewerEPSS 1.0%CVE-2022-23622HIGHCross site scripting in registration template in xwiki-platformEPSS 1.0%CVE-2022-24820MEDIUMUnauthenticated user can list hidden document from multiple velocity templatesEPSS 1.0%CVE-2022-41928CRITICALXWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in AttachmentSelector.xmlEPSS 1.0%CVE-2023-46243CRITICALCode execution via the edit action in XWiki platformEPSS 1.0%CVE-2022-29258HIGHCross-site Scripting in Filter Stream Converter Application in XWiki PlatformEPSS 1.0%CVE-2022-29252HIGHCross-site Scripting in XWiki Platform Wiki UI Main WikiEPSS 1.0%CVE-2021-32732HIGHCross-Site Request Forgery in xwiki-platformEPSS 1.0%CVE-2025-48063MEDIUMXWiki Platform Security Authorization Bridge allows users with just edit right can enforce required rights with programming rightEPSS 1.0%CVE-2023-34467HIGHXWiki Platform may retrieve email addresses of all users EPSS 1.0%CVE-2022-23620MEDIUMPath traversal in xwiki-platform-skin-skinxEPSS 1.0%CVE-2022-23617MEDIUMMissing authorization in xwiki-platformEPSS 0.9%CVE-2023-29206CRITICALorg.xwiki.platform:xwiki-platform-skin-skinx vulnerable to basic Cross-site Scripting by exploiting JSX or SSX pluginsEPSS 0.9%CVE-2022-23621MEDIUMMissing authorization in xwiki-platformEPSS 0.9%CVE-2025-29925HIGHXWiki allows unregistered users to access private pages information through REST endpointEPSS 0.9%CVE-2023-29208HIGHData leak through deleted documents EPSS 0.9%CVE-2023-26471CRITICALXWiki Platform users may execute anything with superadmin right through comments and async macroEPSS 0.9%CVE-2023-36477CRITICALPersistent Cross-site Scripting (XSS) through CKEditor Configuration pages in XWiki PlatformEPSS 0.9%CVE-2023-29507CRITICALorg.xwiki.platform:xwiki-platform-oldcore makes Incorrect Use of Privileged APIs with DocumentAuthorsEPSS 0.9%CVE-2023-26476HIGHTwo XWiki Platform UIs Expose Sensitive Information to an Unauthorized ActorEPSS 0.9%