Skip to main content

Vendor archive

xwiki CVEs

Beta · best-effort

282 CVEs tagged to vendor xwiki129 Critical, 76 High, 69 Medium, 8 Low, 0 Unrated.

CVE-2025-51846

Published Apr 30, 2026

CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users of a CryptPad instance. Fixed…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2026-40105

Published Apr 15, 2026

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 10.4-rc-1, through 16.10.15, 17.0.0-rc-1, through 17.4.7 and 17.…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-40104

Published Apr 15, 2026

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 1.8-rc-1, 17.0.0-rc-1 and 17.5.0-rc-1 and prior include a resourc…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2026-33229

Published Apr 8, 2026

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows…

CVSS 8.6 · High
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2025-66024

Published Mar 4, 2026

The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2026-26000

Published Feb 12, 2026

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.9.0, 17.4.6, and 16.10.13, it's possible using comments to inj…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-24128

Published Jan 24, 2026

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 7.0-milestone-2 through 16.10.11, 17.0.0-rc-1 through 17.4.4, and…

CVSS 6.5 · Medium
evidence mentions
6
Buzz score
26.0
Vendor/product tagsBeta · best-effort

CVE-2025-65091

Published Jan 10, 2026

XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right to view the Calendar.JSONService page (including guest users…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-65090

Published Jan 10, 2026

XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.6, users with the rights to view the Calendar.JSONService page (including guest user…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-66474

Published Dec 10, 2025

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Versions 16.10.9 and below,…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66473

Published Dec 10, 2025

XWiki is an open-source wiki software platform. Versions 16.10.10 and below, 17.0.0-rc-1 through 17.4.3 and 17.5.0-rc-1 through 17.6.0 contain a REST API which doesn't enforce any…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-66472

Published Dec 10, 2025

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 6.2-milestone-1 through 16.10.9 and 17.0.0-rc-1 through 17.4.1 o…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-65036

Published Dec 5, 2025

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to 1.27.1, the macro executes Velocity from the details pages wit…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-55749

Published Dec 1, 2025

XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is using the XWiki Jetty package (XJetty), a context is exposed to…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-65089

Published Nov 19, 2025

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to version 1.27.0, a user with no view rights on a page may see t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55728

Published Sep 9, 2025

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping o…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-55727

Published Sep 9, 2025

XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping o…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-55748

Published Sep 3, 2025

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-2 through 16.10.6, configuration files are acces…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-55747

Published Sep 3, 2025

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 6.1-milestone-2 through 16.10.6, configuration files are acce…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-58049

Published Aug 28, 2025

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions from 14.4.2 to before 16.4.8, 16.5.0-rc-1 to before 16.10.7, a…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-51991

Published Aug 20, 2025

XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, specifically within the HTTP Meta Info field of the Global Pre…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-51990

Published Aug 20, 2025

XWiki through version 17.3.0 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities in the Administration interface, specifically under the Presentation section…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54125

Published Aug 6, 2025

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 1.1 th…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-54124

Published Aug 6, 2025

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 9.8-rc…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-32430

Published Aug 6, 2025

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-3 through 16.4.7, 16.5.0-rc-1 through 16.10.5 an…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort
Showing 1-25 of 282 CVEsPage 1 of 12