Vulnerabilidades en xwiki

250 resultados
Análisis Vexday

O XWiki acumula 245 CVEs catalogadas, das quais 121 são classificadas como severidade crítica — concentração expressiva que merece atenção contínua de equipes de gestão de vulnerabilidades. A taxa de exploração ativa está em linha com a média geral do catálogo, mas o CVE-2025-24893 se destaca com EPSS de 0,999, indicando probabilidade máxima de exploração ativa segundo os modelos preditivos, e já figura no catálogo KEV da CISA. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que costuma refletir gaps estruturais no tratamento de entrada e saída de dados na plataforma. Com 9 CVEs com PoC pública e 5 surgidas nos últimos 90 dias, o ritmo de descoberta recente reforça a necessidade de monitoramento contínuo e aplicação prioritária de patches.

CVE-2025-49586HIGHXWiki allows remote code execution through preview of XClass changes in AWM editorEPSS 0.7%CVE-2023-27480HIGHData leak through a XAR import XXE attack in xwiki-platform-xar-modelEPSS 0.7%CVE-2023-35153CRITICALXWiki Platform vulnerable to stored cross-site scripting in ClassEditSheet page via name parametersEPSS 0.7%CVE-2024-55663HIGHXWiki Platform has an SQL injection in getdocuments.vm with sort parameterEPSS 0.7%CVE-2022-41929MEDIUMMissing Authorization in User#setDisabledStatus in org.xwiki.platform:xwiki-platform-oldcoreEPSS 0.7%CVE-2023-35151HIGHXWiki Platform may show email addresses in clear in REST resultsEPSS 0.7%CVE-2023-34464CRITICALXWiki vulnerable to stored cross-site scripting via any wiki document and the displaycontent/rendercontent templateEPSS 0.7%CVE-2023-48240CRITICALXWiki Platform sends cookies to external images in rendered diff and is vulnerable to server side request forgeryEPSS 0.7%CVE-2024-31988CRITICALXWiki Platform CSRF remote code execution through the realtime HTML Converter APIEPSS 0.7%CVE-2024-37899CRITICALDisabling a user account changes its author, allowing RCE from user account in XWikiEPSS 0.7%CVE-2023-29203LOWUnauthenticated user can have information about hidden users on subwikis through uorgsuggest.vm EPSS 0.7%CVE-2022-23615MEDIUMPartial authorization bypass on document save in xwiki-platformEPSS 0.7%CVE-2024-43401CRITICALIn XWiki Platform, payloads stored in content is executed when a user with script/programming right edit themEPSS 0.7%CVE-2023-29513MEDIUMUsers can be created even when registration is disabled without validation via the template macro in xwiki-platformEPSS 0.7%CVE-2023-26480HIGHXWiki-Platform vulnerable to stored Cross-site Scripting via the HTML displayer in Live DataEPSS 0.7%CVE-2023-26478MEDIUMorg.xwiki.platform:xwiki-platform-store-filesystem-oldcore has Exposed Dangerous Method or FunctionEPSS 0.7%CVE-2023-37277CRITICALXWiki Platform vulnerable to cross-site request forgery (CSRF) via the REST APIEPSS 0.7%CVE-2023-50722CRITICALXWiki Platform XSS/CSRF Remote Code Execution in XWiki.ConfigurableClassEPSS 0.7%CVE-2023-32070CRITICALImproper Neutralization of Script in Attributes in XWiki (X)HTML renderersEPSS 0.7%CVE-2025-53837CRITICALorg.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issueEPSS 0.6%