org.xwiki.platform:xwiki-platform-web-templates
Maven20 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.xwiki.platform:xwiki-platform-web-templatespage 1 of 1
- CVE-2022-23622HIGHCVSS 7.4EG 7.4✓ Fixed in 13.10.32022-02-09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions there is a cross site scripting (XSS) vector in the `registerinline.vm` template related to the `xredirect` hidde…
- CVE-2022-24819MEDIUMCVSS 5.3EG 5.3✓ Fixed in 13.92022-04-08
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents related to users of the wiki. The problem has been p…
- CVE-2022-36091HIGHCVSS 7.5EG 7.5✓ Fixed in 13.10.42022-09-08
XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. Through the suggestion feature, string and list properties of objects the user shouldn't have access to can be accessed in versions prior to 13.10.4 an…
- CVE-2022-36093HIGHCVSS 8.5EG 8.5✓ Fixed in 14.3-rc-12022-09-08
XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. By passing a template of the distribution wizard to the xpart template, user accounts can be created even when user registration is disabled. This also…
- CVE-2022-36095MEDIUMCVSS 4.3EG 4.3✓ Fixed in 14.32022-09-08
XWiki Platform is a generic wiki platform. Prior to versions 13.10.5 and 14.3, it is possible to perform a Cross-Site Request Forgery (CSRF) attack for adding or removing tags on XWiki pages. The problem has been patched in XWiki 13.10.5 a…
- CVE-2023-29203LOWCVSS 3.7EG 3.7✓ Fixed in 14.7-rc-12023-04-15
XWiki Commons are technical libraries common to several other top level XWiki projects. It's possible to list some users who are normally not viewable from subwiki by requesting users on a subwiki which allows only global users with `uorgs…
- CVE-2023-29207HIGHCVSS 8.9EG 8.9✓ Fixed in 14.92023-04-15
XWiki Commons are technical libraries common to several other top level XWiki projects. The Livetable Macro wasn't properly sanitizing column names, thus allowing the insertion of raw HTML code including JavaScript. This vulnerability was…
- CVE-2023-29512CRITICALCVSS 9.9EG 9.9✓ Fixed in 14.10.12023-04-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on a page (e.g., it's own user page), can execute arbitrary Groovy, Python or Velocity code in XWiki leading…
- CVE-2023-29513MEDIUMCVSS 5.0EG 5.0✓ Fixed in 14.10.12023-04-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. If guest has view right on any document. It's possible to create a new user using the `distribution/firstadminuser.wiki` in the wrong …
- CVE-2023-34464CRITICALCVSS 9.0EG 9.0✓ Fixed in 15.1-rc-12023-06-23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.2.1 until versions 14.4.8, 14.10.5, and 15.1RC1 of org.xwiki.platform:xwiki-platform-web and any version prior t…
- CVE-2023-35159CRITICALCVSS 9.6EG 9.6✓ Fixed in 15.1-rc-12023-06-23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the deletespac…
- CVE-2023-35160CRITICALCVSS 9.6EG 9.6✓ Fixed in 15.1-rc-12023-06-23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the resubmit t…
- CVE-2023-40176CRITICALCVSS 9.0EG 9.0✓ Fixed in 14.10.52023-08-23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can exploit a stored XSS through their user profile by setting the payload as the value of the time zone user pref…
- CVE-2023-45134CRITICALCVSS 9.0EG 9.0✓ Fixed in 15.5-rc-12023-10-25
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. `org.xwiki.platform:xwiki-platform-web` starting in version 3.1-milestone-1 and prior to 13.4-rc-1, `org.xwiki.platform:xwiki-platform…
- CVE-2023-45135CRITICALCVSS 9.0EG 9.0✓ Fixed in 15.5-rc-12023-10-25
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In `org.xwiki.platform:xwiki-platform-web` versions 7.2-milestone-2 until 14.10.12 and `org.xwiki.platform:xwiki-platform-web-template…
- CVE-2023-45136CRITICALCVSS 9.6EG 9.6✓ Fixed in 15.5-rc-12023-10-25
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When document names are validated according to a name strategy (disabled by default), XWiki starting in version 12.0-rc-1 and prior to…
- CVE-2023-45137CRITICALCVSS 9.0EG 9.0✓ Fixed in 15.5-rc-12023-10-25
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. `org.xwiki.platform:xwiki-platform-web` starting in version 3.1-milestone-2 and prior to version 13.4-rc-1, as well as `org.xwiki.plat…
- CVE-2024-41947CRITICALCVSS 9.0EG 9.0✓ Fixed in 16.3.0-rc-12024-07-31
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a conflict when another user with more rights is currently editing a page, it is possible to execute JavaScript snippets o…
- CVE-2024-43401CRITICALCVSS 9.0EG 9.0✓ Fixed in 15.10-rc-12024-08-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIW…
- CVE-2026-40105MEDIUMCVSS 6.1EG 6.1✓ Fixed in 17.10.12026-04-15
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 10.4-rc-1, through 16.10.15, 17.0.0-rc-1, through 17.4.7 and 17.5.0-rc-1 through 17.10.0 contain a reflected cross-site scri…
Check whether org.xwiki.platform:xwiki-platform-web-templates is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.xwiki.platform:xwiki-platform-web-templates CVEs against the assets you own.
Start Free Scan →