org.xwiki.platform:xwiki-platform-attachment-ui
Maven4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.xwiki.platform:xwiki-platform-attachment-uipage 1 of 1
- CVE-2022-36097HIGHCVSS 8.9EG 8.9✓ Fixed in 14.4-rc-12022-09-08
XWiki Platform Attachment UI provides a macro to easily upload and select attachments for XWiki Platform, a generic wiki platform. Starting with version 14.0-rc-1 and prior to 14.4-rc-1, it's possible to store JavaScript in an attachment n…
- CVE-2022-41928CRITICALCVSS 9.9EG 9.9✓ Fixed in 14.4.22022-11-23
XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in AttachmentSelector.xml. The issue can also be reproduced by inserting the dangerous payload in the `height` or `alt` mac…
- CVE-2023-29516CRITICALCVSS 9.9EG 9.9✓ Fixed in 14.10.12023-04-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on `XWiki.AttachmentSelector` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full…
- CVE-2023-29519CRITICALCVSS 9.0EG 9.0✓ Fixed in 14.10.22023-04-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A registered user can perform remote code execution leading to privilege escalation by injecting the proper code in the "property" fie…
Check whether org.xwiki.platform:xwiki-platform-attachment-ui is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.xwiki.platform:xwiki-platform-attachment-ui CVEs against the assets you own.
Start Free Scan →