Exposição de XWiki

Wikis
324
score de exposição
32
sites usam
1
em exploração
122
críticos
Análise Vexday

Com 245 CVEs catalogadas, o XWiki apresenta um volume expressivo de vulnerabilidades, sendo 121 delas de severidade crítica — número que por si só justifica atenção redobrada em ambientes que utilizam a plataforma. A falha mais comum é CWE-79 (Cross-Site Scripting), padrão que, em wikis colaborativos com renderização de conteúdo rico, tende a ter superfície de ataque ampla e impacto relevante sobre usuários autenticados. A CVE mais perigosa atualmente ativa é CVE-2025-24893, com score EPSS de 0,999 — valor que indica probabilidade extremamente alta de exploração ativa —, exigindo priorização imediata de remediação. A taxa de exploração confirmada no CISA KEV está em linha com a média geral do catálogo, mas o EPSS elevado dessa CVE sugere que a exposição real pode ser significativamente maior do que o número de entradas KEV indica.

CVEs

250 resultados
CVE-2023-29521HIGHCode injection from account/view through VFS Tree macro in xwiki-platformEPSS 1.1%CVE-2022-23619MEDIUMInformation exposure in xwiki-platformEPSS 1.1%CVE-2021-29459CRITICALXSS Cross Site ScriptingEPSS 1.1%CVE-2023-26472CRITICALXWiki Platform vulnerable to privilege escalation via async macro and IconThemeSheet from the user profileEPSS 1.1%CVE-2023-29527CRITICALCode injection from account through AWM view sheet in xwiki platformEPSS 1.1%CVE-2023-26479MEDIUMorg.xwiki.platform:xwiki-platform-rendering-parser vulnerable to Improper Handling of Exceptional ConditionsEPSS 1.1%CVE-2023-40573CRITICALXWiki Platform's Groovy jobs check the wrong author, allowing remote code executionEPSS 1.1%CVE-2023-37913CRITICALorg.xwiki.platform:xwiki-platform-office-importer vulnerable to arbitrary server side file writing from account through office converterEPSS 1.1%CVE-2024-55879CRITICALXWiki allows RCE from script right in configurable sectionsEPSS 1.1%CVE-2025-46554MEDIUMXWiki missing authorization when accessing the wiki level attachments list and metadata via REST APIEPSS 1.1%CVE-2023-40177CRITICALXWiki Platform privilege escalation (PR) from account through AWM content fieldsEPSS 1.1%CVE-2023-37908CRITICALorg.xwiki.rendering:xwiki-rendering-xml Improper Neutralization of Invalid Characters in Identifiers in Web Pages vulnerabilityEPSS 1.1%CVE-2024-37901CRITICALXWiki Platform vulnerable to remote code execution from account via SearchSuggestConfigSheetEPSS 1.1%CVE-2022-36092HIGHXWiki Platform Old Core vulnerable to Authentication Bypass Using the Login ActionEPSS 1.1%CVE-2022-29253LOWPath Traversal in XWiki PlatformEPSS 1.1%CVE-2023-30537CRITICALorg.xwiki.platform:xwiki-platform-flamingo-theme-ui vulnerable to privilege escalationEPSS 1.0%CVE-2023-29511CRITICALxwiki-platform-administration-ui vulnerable to privilege escalationEPSS 1.0%CVE-2023-36471CRITICALHTML sanitizer allows form elements in restricted in org.xwiki.commons:xwiki-commons-xmlEPSS 1.0%CVE-2025-66474HIGHXWiki vulnerable to remote code execution through insufficient protection against {{/html}} injectionEPSS 1.0%CVE-2023-35152CRITICALXWiki Platform vulnerable to privilege escalation (PR) from account through like LiveTableResultsEPSS 1.0%