org.xwiki.platform:xwiki-platform-distribution-war
Maven4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.xwiki.platform:xwiki-platform-distribution-warpage 1 of 1
- CVE-2023-29525CRITICALCVSS 9.9EG 9.9✓ Fixed in 14.6-rc-12023-04-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Affected versions of xwiki are subject to code injection in the `since` parameter of the `/xwiki/bin/view/XWiki/Notifications/Code/Leg…
- CVE-2023-32071CRITICALCVSS 9.0EG 9.0✓ Fixed in 14.10.42023-05-09
XWiki Platform is a generic wiki platform. Starting in versions 2.2-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, it's possible to execute javascript with the right of any user by leading him to a special URL on the wik…
- CVE-2024-21651HIGHCVSS 7.5EG 7.5✓ Fixed in 15.8-rc-12024-01-09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user able to attach a file to a page can post a malformed TAR file by manipulating file modification times headers, which when parse…
- CVE-2024-55663CRITICALCVSS 9.8EG 9.8✓ Fixed in 14.3-rc-12024-12-12
XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 13.10.5 and 14.3-rc-1, in `getdocument.vm`; the ordering of the returned documents is defined from an unsanitized request parameter (reque…
Check whether org.xwiki.platform:xwiki-platform-distribution-war is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.xwiki.platform:xwiki-platform-distribution-war CVEs against the assets you own.
Start Free Scan →