org.xwiki.platform:xwiki-platform-icon-ui
Maven3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.xwiki.platform:xwiki-platform-icon-uipage 1 of 1
- CVE-2022-41931CRITICALCVSS 9.9EG 9.9✓ Fixed in 14.4.22022-11-23
xwiki-platform-icon-ui is vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection'). Any user with view rights on commonly accessible documents including the icon picker macro can execute arbitrar…
- CVE-2023-26472CRITICALCVSS 9.9EG 9.9✓ Fixed in 14.92023-03-02
XWiki Platform is a generic wiki platform. Starting in version 6.2-milestone-1, one can execute any wiki content with the right of IconThemeSheet author by creating an icon theme with certain content. This can be done by creating a new pag…
- CVE-2023-36470CRITICALCVSS 9.9EG 9.9✓ Fixed in 15.2-rc-12023-06-29
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By either creating a new or editing an existing document with an icon set, an attacker can inject XWiki syntax and Velocity code that …
Check whether org.xwiki.platform:xwiki-platform-icon-ui is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.xwiki.platform:xwiki-platform-icon-ui CVEs against the assets you own.
Start Free Scan →