CVEs we hold for Xwiki-platform
Records whose assigning authority named Xwiki-platform as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-53966XWiki Platform: Privilege escalation from edit to script right through Live Data editingxwiki-platform
CVE-2026-48048XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requestsxwiki-platform
CVE-2026-48047XWiki Platform vulnerable to potential arbitrary file writing using path traversal from (subwiki) adminxwiki-platform
CVE-2026-40105XWiki has Reflected Cross-Site Scripting (XSS) in its page history compare functionalityxwiki-platform
CVE-2026-34151XWiki Platform: Resource path traversal via /skin/ action endpoint in Jetty 12+xwiki-platform
CVE-2026-33229XWiki Platform affected by remote code execution with script right through unprotected Velocity scripting APIxwiki-platform; org.xwiki.platform…
CVE-2026-33137XWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName}xwiki-platform
CVE-2026-26000XWiki Platform affected by click-jacking through CSS injection in commentsxwiki-platform
CVE-2026-24128XWiki Affected by Reflected Cross-Site Scripting (XSS) in Error Messagesxwiki-platform
CVE-2025-66473XWiki's REST APIs don't enforce any limits, leading to unavailability and OOM in large wikisxwiki-platform
CVE-2025-66472XWiki vulnerable to a reflected XSS via xredirect parameter in DeleteApplicationxwiki-platform
CVE-2025-58049XWiki PDF export jobs store sensitive cookies unencrypted in job statusesxwiki-platform
CVE-2025-55749The XWiki Jetty package (XJetty) allows accessing any application file through URLxwiki-platform
CVE-2025-55748XWiki Platform's configuration files can be accessed through jsx and sx endpointsxwiki-platform
CVE-2025-55747XWiki Platform's configuration files can be accessed through the webjars APIxwiki-platform
CVE-2025-54124XWiki Platform: Any user with editing rights can access password properties through Database List Propertiesxwiki-platform
CVE-2025-52472XWiki Platform vulnerable to HQL injection via wiki and space search REST APIxwiki-platform
CVE-2025-49587XWiki does not require right warnings for notification displayer objectsxwiki-platform
CVE-2025-49586XWiki allows remote code execution through preview of XClass changes in AWM editorxwiki-platform
CVE-2025-49584XWiki makes title of inaccessible pages available through the class property values REST APIxwiki-platform
CVE-2025-49583XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin rightxwiki-platform
CVE-2025-49581XWiki allows remote code execution through default value of wiki macro wiki-type parametersxwiki-platform
CVE-2025-48063XWiki Platform Security Authorization Bridge allows users with just edit right can enforce required rights with…xwiki-platform
CVE-2025-46557Any user with view access to the XWiki space can change the authenticatorxwiki-platform
CVE-2025-46554XWiki missing authorization when accessing the wiki level attachments list and metadata via REST APIxwiki-platform
CVE-2025-32974org.xwiki.platform:xwiki-platform-security-requiredrights-default required rights analysis doesn't consider TextAreas…xwiki-platform
CVE-2025-32973org.xwiki.platform:xwiki-platform-component-wiki provides no warning when granting XWiki.ComponentClass programming…xwiki-platform
CVE-2025-32972The lesscss script service allows cache clearing without programming rightxwiki-platform
CVE-2025-32971XWiki Solr script service doesn't take dropped programming right into accountxwiki-platform
CVE-2025-32970org.xwiki.platform:xwiki-platform-wysiwyg-api Open Redirect vulnerabilityxwiki-platform
CVE-2025-32969org.xwiki.platform:xwiki-platform-rest-server allows SQL injection in query endpoint of REST APIxwiki-platform
CVE-2025-32968org.xwiki.platform:xwiki-platform-oldcore allows SQL injection in short form select requests through the script query…xwiki-platform
CVE-2025-32783XWiki allows unregistered users to see "public" messages from a closed wiki via notifications from a different wikixwiki-platform
CVE-2025-32429XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameterxwiki-platform
CVE-2025-29925XWiki allows unregistered users to access private pages information through REST endpointxwiki-platform
CVE-2024-55877XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosListxwiki-platform
CVE-2024-55876XWiki's scheduler in subwiki allows scheduling operations for any main wiki userxwiki-platform
CVE-2024-55663XWiki Platform has an SQL injection in getdocuments.vm with sort parameterxwiki-platform
CVE-2024-46978Missing checks for notification filter preferences editions in XWiki Platformxwiki-platform
CVE-2024-45591XWiki Platform document history including authors of any page exposed to unauthorized actorsxwiki-platform
CVE-2024-43401In XWiki Platform, payloads stored in content is executed when a user with script/programming right edit themxwiki-platform
CVE-2024-37901XWiki Platform vulnerable to remote code execution from account via SearchSuggestConfigSheetxwiki-platform
CVE-2024-37900XWiki Platform vulnerable to Cross-site Scripting through attachment filename in uploaderxwiki-platform
CVE-2024-37899Disabling a user account changes its author, allowing RCE from user account in XWikixwiki-platform
CVE-2024-31997XWiki Platform remote code execution from account through UIExtension parametersxwiki-platform
CVE-2024-31988XWiki Platform CSRF remote code execution through the realtime HTML Converter APIxwiki-platform
CVE-2024-31987XWiki Platform remote code execution from account via custom skins supportxwiki-platform
CVE-2024-31986XWiki Platform CSRF remote code execution through scheduler job's document referencexwiki-platform
CVE-2024-31984XWiki Platform: Remote code execution through space title and Solr space facetxwiki-platform
CVE-2024-31983XWiki Platform: Remote code execution from edit in multilingual wikis via translationsxwiki-platform
CVE-2024-31981XWiki Platform: Privilege escalation (PR) from user registration through PDFClassxwiki-platform
CVE-2024-31465XWiki Platform: Remote code execution from account via SearchSuggestSourceSheetxwiki-platform
CVE-2024-31464XWiki Platform: Password hash might be leaked by diff once the xobject holding them is deletedxwiki-platform
CVE-2023-50723XWiki Platform remote code execution/programming rights with configuration section from any user accountxwiki-platform
CVE-2023-50722XWiki Platform XSS/CSRF Remote Code Execution in XWiki.ConfigurableClassxwiki-platform
CVE-2023-48241XWiki exposed whole content of all documents of all wikis to anybody with view right on Solr suggest servicexwiki-platform
CVE-2023-48240XWiki Platform sends cookies to external images in rendered diff and is vulnerable to server side request forgeryxwiki-platform
CVE-2023-46732Reflected Cross-site scripting through revision parameter in content menu in XWiki Platformxwiki-platform
CVE-2023-46731Remote code execution through the section parameter in Administration as guest in XWiki Platformxwiki-platform
CVE-2023-45137XWiki Platform XSS with edit right in the create document form for existing pagesxwiki-platform
CVE-2023-45136XWiki Platform web templates vulnerable to reflected XSS in the create document form if name validation is enabledxwiki-platform
CVE-2023-45135XWiki users can be tricked to execute scripts as the create page action doesn't display the page's titlexwiki-platform
CVE-2023-45134XWiki Platform XSS vulnerability from account in the create page form via template providerxwiki-platform
CVE-2023-40573XWiki Platform's Groovy jobs check the wrong author, allowing remote code executionxwiki-platform
CVE-2023-40572XWiki Platform vulnerable to CSRF privilege escalation/RCE via the create actionxwiki-platform
CVE-2023-40177XWiki Platform privilege escalation (PR) from account through AWM content fieldsxwiki-platform
CVE-2023-37914Privilege escalation (PR)/RCE from account through Invitation subject/messagexwiki-platform
CVE-2023-37913org.xwiki.platform:xwiki-platform-office-importer vulnerable to arbitrary server side file writing from account through…xwiki-platform
CVE-2023-37911org.xwiki.platform:xwiki-platform-oldcore may leak data through deleted and re-created documentsxwiki-platform
CVE-2023-37910org.xwiki.platform:xwiki-platform-attachment-api vulnerable to Missing Authorization on Attachment Movexwiki-platform
CVE-2023-37909Privilege escalation (PR)/remote code execution from account through Menu.UIExtensionSheetxwiki-platform
CVE-2023-37462Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in…xwiki-platform
CVE-2023-37277XWiki Platform vulnerable to cross-site request forgery (CSRF) via the REST APIxwiki-platform
CVE-2023-36477Persistent Cross-site Scripting (XSS) through CKEditor Configuration pages in XWiki Platformxwiki-platform
CVE-2023-35162XPlatform Wiki vulnerable to cross-site scripting via xcontinue parameter in preview actions templatexwiki-platform
CVE-2023-35161XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in DeleteApplication pagexwiki-platform
CVE-2023-35160XWiki Platform vulnerable to reflected cross-site scripting via back and xcontinue parameters in resubmit templatexwiki-platform
CVE-2023-35159XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in deletespace templatexwiki-platform
CVE-2023-35158XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in restore templatexwiki-platform
CVE-2023-35157XWiki Platform vulnerable to reflected cross-site scripting via delattachment actionxwiki-platform
CVE-2023-35156XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in delete templatexwiki-platform
CVE-2023-35155XWiki Platform vulnerable to cross-site scripting in target parameter via share page by emailxwiki-platform
CVE-2023-35153XWiki Platform vulnerable to stored cross-site scripting in ClassEditSheet page via name parametersxwiki-platform
CVE-2023-35152XWiki Platform vulnerable to privilege escalation (PR) from account through like LiveTableResultsxwiki-platform
CVE-2023-35150XWiki Platform vulnerable to privilege escalation (PR) from view right via Invitation applicationxwiki-platform
CVE-2023-34465XWiki Platform's Mail.MailConfig can be edited by any user with edit rightsxwiki-platform
CVE-2023-34464XWiki vulnerable to stored cross-site scripting via any wiki document and the displaycontent/rendercontent templatexwiki-platform
CVE-2023-32071XWiki Platform vulnerable to RXSS via editor parameter - importinline templatexwiki-platform
CVE-2023-32069XWiki Platform privilege escalation (PR)/RCE from account through class sheetxwiki-platform
CVE-2023-30537org.xwiki.platform:xwiki-platform-flamingo-theme-ui vulnerable to privilege escalationxwiki-platform
CVE-2023-29526Async and display macro allow displaying and interacting with any document in restricted modexwiki-platform
CVE-2023-29525Privilege escalation from view right on XWiki.Notifications.Code.LegacyNotificationAdministration in xwiki-platformxwiki-platform
CVE-2023-29524Code injection from account through XWiki.SchedulerJobSheet in xwiki-platformxwiki-platform
CVE-2023-29523Code injection in display method used in user profiles in xwiki-platformxwiki-platform
CVE-2023-29521Code injection from account/view through VFS Tree macro in xwiki-platformxwiki-platform
CVE-2023-29518Code injection from view right using Invitation.InvitationCommon in xwiki-platformxwiki-platform
CVE-2023-29517Exposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-office-viewerxwiki-platform
CVE-2023-29516Code injection from view right on XWiki.AttachmentSelector in xwiki-platformxwiki-platform
CVE-2023-29513Users can be created even when registration is disabled without validation via the template macro in xwiki-platformxwiki-platform
CVE-2023-29509org.xwiki.platform:xwiki-platform-flamingo-theme-ui Eval Injection vulnerabilityxwiki-platform
CVE-2023-29508org.xwiki.platform:xwiki-platform-livedata-macro vulnerable to Cross-site Scriptingxwiki-platform
CVE-2023-29507org.xwiki.platform:xwiki-platform-oldcore makes Incorrect Use of Privileged APIs with DocumentAuthorsxwiki-platform
CVE-2023-29506org.xwiki.platform:xwiki-platform-security-authentication-default XSS with authenticated endpointsxwiki-platform
CVE-2023-29214org.xwiki.platform:xwiki-platform-panels-ui Eval Injection vulnerabilityxwiki-platform
CVE-2023-29211org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki Eval Injection vulnerabilityxwiki-platform
CVE-2023-29210org.xwiki.platform:xwiki-platform-notifications-ui Eval Injection vulnerabilityxwiki-platform
CVE-2023-29209org.xwiki.platform:xwiki-platform-legacy-notification-activitymacro Eval Injection vulnerabilityxwiki-platform
CVE-2023-29207Improper Neutralization of Script-Related HTML Tags (XSS) in the LiveTable Macroxwiki-platform
CVE-2023-29206org.xwiki.platform:xwiki-platform-skin-skinx vulnerable to basic Cross-site Scripting by exploiting JSX or SSX pluginsxwiki-platform
CVE-2023-29205org.xwiki.platform:xwiki-platform-rendering-xwiki vulnerable to stored cross-site scripting via HTML and raw macroxwiki-platform
CVE-2023-29204URL Redirection to Untrusted Site ('Open Redirect') in org.xwiki.platform:xwiki-platform-oldcorexwiki-platform
CVE-2023-29203Unauthenticated user can have information about hidden users on subwikis through uorgsuggest.vmxwiki-platform
CVE-2023-29202org.xwiki.platform:xwiki-platform-rendering-macro-rss Cross-site Scripting vulnerabilityxwiki-platform
CVE-2023-27479Improper Neutralization of Directives in Dynamically Evaluated Code in org.xwiki.platform:xwiki-platform-panels-uixwiki-platform
CVE-2023-26480XWiki-Platform vulnerable to stored Cross-site Scripting via the HTML displayer in Live Dataxwiki-platform
CVE-2023-26479org.xwiki.platform:xwiki-platform-rendering-parser vulnerable to Improper Handling of Exceptional Conditionsxwiki-platform
CVE-2023-26478org.xwiki.platform:xwiki-platform-store-filesystem-oldcore has Exposed Dangerous Method or Functionxwiki-platform
CVE-2023-26477org.xwiki.platform:xwiki-platform-flamingo-theme-ui Eval Injection vulnerabilityxwiki-platform
CVE-2023-26476Two XWiki Platform UIs Expose Sensitive Information to an Unauthorized Actorxwiki-platform
CVE-2023-26474XWiki Platform vulnerable to privilege escalation via properties with wiki syntax that are executed with wrong authorxwiki-platform
CVE-2023-26473XWiki Platform allows unprivileged users to make arbitrary select queries using DatabaseListProperty and suggest.vmxwiki-platform
CVE-2023-26472XWiki Platform vulnerable to privilege escalation via async macro and IconThemeSheet from the user profilexwiki-platform
CVE-2023-26471XWiki Platform users may execute anything with superadmin right through comments and async macroxwiki-platform
CVE-2023-26470In XWiki Platform, saving a document with a large object number leads to persistent OOM errorsxwiki-platform
CVE-2023-26056XWiki Platform allows macro execution as any user without programming rights through the context macroxwiki-platform
CVE-2022-41936Exposure of Private Personal Information to an Unauthorized Actor in xwiki-platform-rest-serverxwiki-platform
CVE-2022-41935Exposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-livetable-uixwiki-platform
CVE-2022-41934Improper Neutralization of Directives in Dynamically Evaluated Code in org.xwiki.platform:xwiki-platform-menu-uixwiki-platform
CVE-2022-41933Plaintext storage of password in org.xwiki.platform:xwiki-platform-security-authentication-defaultxwiki-platform
CVE-2022-41931Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in xwiki-platform-icon-uixwiki-platform
CVE-2022-41930org.xwiki.platform:xwiki-platform-user-profile-ui missing authorization to enable or disable usersxwiki-platform
CVE-2022-41929Missing Authorization in User#setDisabledStatus in org.xwiki.platform:xwiki-platform-oldcorexwiki-platform
CVE-2022-41928XWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in…xwiki-platform
CVE-2022-41927XWiki Platform vulnerable to Cross-Site Request Forgery (CSRF) allowing to delete or rename tagsxwiki-platform
CVE-2022-36100XWiki Platform Applications Tag and XWiki Platform Tag UI vulnerable to Eval Injectionxwiki-platform
CVE-2022-36097XWiki Platform Attachment UI vulnerable to cross-site scripting in the move attachment formxwiki-platform
CVE-2022-36096XWiki Platform vulnerable to Cross-site Scripting in the deleted attachments listxwiki-platform
CVE-2022-36094XWiki Platform Web Parent POM vulnerable to XSS in the attachment historyxwiki-platform
CVE-2022-36093XWiki Platform Web Templates vulnerable to Unauthorized User Registration Through the Distribution Wizardxwiki-platform
CVE-2022-36092XWiki Platform Old Core vulnerable to Authentication Bypass Using the Login Actionxwiki-platform
200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.