Vulnerabilidades em xwiki

250 resultados
Análise Vexday

O XWiki acumula 245 CVEs catalogadas, das quais 121 são classificadas como severidade crítica — concentração expressiva que merece atenção contínua de equipes de gestão de vulnerabilidades. A taxa de exploração ativa está em linha com a média geral do catálogo, mas o CVE-2025-24893 se destaca com EPSS de 0,999, indicando probabilidade máxima de exploração ativa segundo os modelos preditivos, e já figura no catálogo KEV da CISA. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que costuma refletir gaps estruturais no tratamento de entrada e saída de dados na plataforma. Com 9 CVEs com PoC pública e 5 surgidas nos últimos 90 dias, o ritmo de descoberta recente reforça a necessidade de monitoramento contínuo e aplicação prioritária de patches.

CVE-2025-52472CRITICALXWiki Platform vulnerable to HQL injection via wiki and space search REST APIEPSS 2.4%CVE-2023-35160CRITICALXWiki Platform vulnerable to reflected cross-site scripting via back and xcontinue parameters in resubmit templateEPSS 2.3%CVE-2023-46732CRITICALReflected Cross-site scripting through revision parameter in content menu in XWiki PlatformEPSS 2.2%CVE-2023-35159CRITICALXWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in deletespace templateEPSS 2.2%CVE-2020-11057CRITICALCode Injection in XWiki PlatformEPSS 2.2%CVE-2024-31996CRITICALXWiki Commons missing escaping of `{` in Velocity escapetool allows remote code executionEPSS 2.1%CVE-2021-32621HIGHScript injection without script or programming rights through Gadget titlesEPSS 2.1%CVE-2022-23616HIGHRemote code execution in xwiki-platformEPSS 2.1%CVE-2023-35156CRITICALXWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in delete templateEPSS 2.1%CVE-2023-35158CRITICALXWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in restore templateEPSS 2.0%CVE-2023-29523CRITICALCode injection in display method used in user profiles in xwiki-platformEPSS 2.0%CVE-2023-29519CRITICALCode injection in org.xwiki.platform:xwiki-platform-attachment-uiEPSS 1.9%CVE-2023-36470CRITICALCode injection in icon themes of XWiki PlatformEPSS 1.9%CVE-2023-37914CRITICALPrivilege escalation (PR)/RCE from account through Invitation subject/messageEPSS 1.9%CVE-2023-29522CRITICALCode injection from view right on XWiki.ClassSheet in xwiki-platformEPSS 1.9%CVE-2023-29510CRITICALCode injection via unescaped translations in xwiki-platformEPSS 1.9%CVE-2023-29514CRITICALCode injection in template provider administration in xwiki-platformEPSS 1.9%CVE-2023-36468CRITICALUpgrading doesn't prevent exploiting vulnerable XWiki documentsEPSS 1.9%CVE-2023-45134CRITICALXWiki Platform XSS vulnerability from account in the create page form via template providerEPSS 1.8%CVE-2025-55748CRITICALXWiki Platform's configuration files can be accessed through jsx and sx endpointsEPSS 1.8%