org.xwiki.platform:xwiki-platform-web
Maven15 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.xwiki.platform:xwiki-platform-webpage 1 of 1
- CVE-2020-13654HIGHCVSS 7.5EG 7.5✓ Fixed in 12.82020-12-31
XWiki Platform before 12.8 mishandles escaping in the property displayer.
- CVE-2021-29459CRITICALCVSS 9.6EG 9.6✓ Fixed in 12.82021-04-20
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible to persistently inject scripts in XWiki versions prior to 12.6.3 and 12.8. Unregistred users can fill simple text field…
- CVE-2021-32731MEDIUMCVSS 5.3EG 5.3✓ Fixed in 13.22021-07-01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Between (and including) versions 13.1RC1 and 13.1, the reset password form reveals the email address of users just by giving their use…
- CVE-2022-23619MEDIUMCVSS 5.3EG 5.3✓ Fixed in 12.10.92022-02-09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to guess if a user has an account on the wiki by using the "Forgot your password" form, even if the…
- CVE-2022-24820MEDIUMCVSS 5.3EG 5.3✓ Fixed in 13.92022-04-08
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents by rendering some velocity documents. The problem ha…
- CVE-2022-36091HIGHCVSS 7.5EG 7.5✓ Fixed in 14.22022-09-08
XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. Through the suggestion feature, string and list properties of objects the user shouldn't have access to can be accessed in versions prior to 13.10.4 an…
- CVE-2022-36093HIGHCVSS 8.5EG 8.5✓ Fixed in 14.3-rc-12022-09-08
XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. By passing a template of the distribution wizard to the xpart template, user accounts can be created even when user registration is disabled. This also…
- CVE-2022-36094HIGHCVSS 8.9EG 8.9✓ Fixed in 14.3-rc-12022-09-08
XWiki Platform Web Parent POM contains Web resources for the XWiki platform, a generic wiki platform. Starting with version 1.0 and prior to versions 13.10.6 and 14.30-rc-1, it's possible to store JavaScript which will be executed by anyon…
- CVE-2023-26473MEDIUMCVSS 6.5EG 6.5✓ Fixed in 14.102023-03-02
XWiki Platform is a generic wiki platform. Starting in version 1.3-rc-1, any user with edit right can execute arbitrary database select and access data stored in the database. The problem has been patched in XWiki 13.10.11, 14.4.7, and 14.…
- CVE-2023-29207HIGHCVSS 8.9EG 8.9✓ Fixed in 14.92023-04-15
XWiki Commons are technical libraries common to several other top level XWiki projects. The Livetable Macro wasn't properly sanitizing column names, thus allowing the insertion of raw HTML code including JavaScript. This vulnerability was…
- CVE-2023-34464CRITICALCVSS 9.0EG 9.0✓ Fixed in 14.4.82023-06-23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.2.1 until versions 14.4.8, 14.10.5, and 15.1RC1 of org.xwiki.platform:xwiki-platform-web and any version prior t…
- CVE-2023-45134CRITICALCVSS 9.0EG 9.0✓ Fixed in 13.4-rc-12023-10-25
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. `org.xwiki.platform:xwiki-platform-web` starting in version 3.1-milestone-1 and prior to 13.4-rc-1, `org.xwiki.platform:xwiki-platform…
- CVE-2023-45135CRITICALCVSS 9.0EG 9.0✓ Fixed in 14.10.122023-10-25
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In `org.xwiki.platform:xwiki-platform-web` versions 7.2-milestone-2 until 14.10.12 and `org.xwiki.platform:xwiki-platform-web-template…
- CVE-2023-45137CRITICALCVSS 9.0EG 9.0✓ Fixed in 13.4-rc-12023-10-25
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. `org.xwiki.platform:xwiki-platform-web` starting in version 3.1-milestone-2 and prior to version 13.4-rc-1, as well as `org.xwiki.plat…
- CVE-2026-26000MEDIUMCVSS 6.1EG 6.1✓ Fixed in 17.9.02026-02-12
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.9.0, 17.4.6, and 16.10.13, it's possible using comments to inject CSS that would transform the full wiki in a link area le…
Check whether org.xwiki.platform:xwiki-platform-web is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.xwiki.platform:xwiki-platform-web CVEs against the assets you own.
Start Free Scan →