5 Total advisories
5 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.xwiki.platform:xwiki-platform-legacy-oldcore is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.2
CVE-2026-40104
XWiki's REST APIs can list all pages/spaces, leading to unavailability
UNKNOWN
CVE-2026-33229
XWiki vulnerable to remote code execution with script right through unprotected Velocity scripting API
UNKNOWN
CVE-2025-54125
XWiki exposes passwords and emails stored in fields not named password/email in xml.vm
UNKNOWN
CVE-2025-54124
XWiki leaks password hashes and other accessible password properties
CRITICAL 9.9
CVE-2023-26474
XWiki Platform vulnerable to privilege escalation via properties with wiki syntax that are executed with wrong author
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes