org.xwiki.commons:xwiki-commons-xml
Maven6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.xwiki.commons:xwiki-commons-xmlpage 1 of 1
- CVE-2022-24898MEDIUMCVSS 4.9EG 4.9✓ Fixed in 13.8-rc-12022-04-28
vulnerable: 13.5 ... 13.7-rc-1 (6 versions)
org.xwiki.commons:xwiki-commons-xml is a common module used by other XWiki top level projects. Starting in version 2.7 and prior to versions 12.10.10, 13.4.4, and 13.8-rc-1, it is possible for a script to access any file accessing to the u…
- CVE-2023-26055CRITICALCVSS 9.9EG 9.9✓ Fixed in 14.7-rc-12023-03-02
vulnerable: 14.5, 14.6, 14.6-rc-1
XWiki Commons are technical libraries common to several other top level XWiki projects. Starting in version 3.1-milestone-1, any user can edit their own profile and inject code, which is going to be executed with programming right. The sam…
- CVE-2023-29201CRITICALCVSS 9.0EG 9.0✓ Fixed in 14.6-rc-12023-04-15
vulnerable: 10.0 ... 9.9-rc-2 (365 versions)
XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1, only escaped `<script>` and `<style>`-tags but neither attri…
- CVE-2023-29528CRITICALCVSS 9.0EG 9.0✓ Fixed in 14.102023-04-20
vulnerable: 10.0 ... 9.9-rc-2 (373 versions)
XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1 and massively improved in version 14.6-rc-1, allowed the inje…
- CVE-2023-31126CRITICALCVSS 9.0EG 9.0✓ Fixed in 14.10.42023-05-09
vulnerable: 14.10 ... 14.9-rc-1 (12 versions)
`org.xwiki.commons:xwiki-commons-xml` is an XML library used by the open-source wiki platform XWiki. The HTML sanitizer, introduced in version 14.6-rc-1, allows the injection of arbitrary HTML code and thus cross-site scripting via invalid…
- CVE-2023-36471CRITICALCVSS 9.0EG 9.0✓ Fixed in 15.2-rc-12023-06-29
vulnerable: 15.0, 15.0-rc-1, 15.1, 15.1-rc-1
Xwiki commons is the common modules used by other XWiki top level projects. The HTML sanitizer that is included in XWiki since version 14.6RC1 allowed form and input HTML tags. In the context of XWiki, this allows an attacker without scrip…
Check whether org.xwiki.commons:xwiki-commons-xml is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.xwiki.commons:xwiki-commons-xml CVEs against the assets you own.
Start Free Scan →