46 Total advisories
46 Vulnerabilities
0 Malware
Vulnerabilities
CRITICAL 9.6
CVE-2021-29459
XSS Cross Site Scripting
HIGH 8.5
CVE-2020-15252
RCE in XWiki
MEDIUM 4.1
CVE-2021-43841
Cross-site Scripting by SVG upload in xwiki-platform
MEDIUM 6.6
CVE-2020-15171
Users with SCRIPT right can execute arbitrary code in XWiki
UNKNOWN
CVE-2026-34151
XWiki Platform Old Core: Resource path traversal via /skin/ action endpoint in Jetty 12+
HIGH 8.2
CVE-2026-40104
XWiki's REST APIs can list all pages/spaces, leading to unavailability
UNKNOWN
CVE-2026-33229
XWiki vulnerable to remote code execution with script right through unprotected Velocity scripting API
CRITICAL 9.9
CVE-2023-36468
Upgrading doesn't prevent exploiting vulnerable XWiki documents
UNKNOWN
CVE-2024-56158
XWiki allows SQL injection in query endpoint of REST API with Oracle
UNKNOWN
CVE-2025-54125
XWiki exposes passwords and emails stored in fields not named password/email in xml.vm
UNKNOWN
CVE-2025-54124
XWiki leaks password hashes and other accessible password properties
UNKNOWN
CVE-2025-54385
XWiki Platform vulnerable to SQL injection through XWiki#searchDocuments API
UNKNOWN
CVE-2025-49586
XWiki allows remote code execution through preview of XClass changes in AWM editor
UNKNOWN
CVE-2025-32968
org.xwiki.platform:xwiki-platform-oldcore allows SQL injection in short form select requests through the script query API
CRITICAL 9.1
CVE-2023-29507
org.xwiki.platform:xwiki-platform-oldcore makes Incorrect Use of Privileged APIs with DocumentAuthors
CRITICAL 9.0
CVE-2024-37899
XWiki Platform allows remote code execution from user account
CRITICAL 9.0
CVE-2024-43400
XWiki Platform allows XSS through XClass name in string properties
MEDIUM 4.3
CVE-2024-37898
XWiki Platform vulnerable to document deletion and overwrite from edit
CRITICAL 9.9
CVE-2024-31987
XWiki Platform remote code execution from account via custom skins support
CRITICAL 9.9
CVE-2024-31981
XWiki Platform: Privilege escalation (PR) from user registration through PDFClass
MEDIUM 6.8
CVE-2024-31464
XWiki Platform: Password hash might be leaked by diff once the xobject holding them is deleted
UNKNOWN
CVE-2006-7223
XWiki Remote Code Execution
HIGH 8.0
CVE-2024-21648
XWiki has no right protection on rollback action
HIGH 8.8
CVE-2023-46243
XWiki Platform vulnerable to privilege escalation and remote code execution via the edit action
CRITICAL 9.6
CVE-2023-46242
XWiki Platform vulnerable to remote code execution via the edit action because it lacks CSRF token
MEDIUM 6.3
CVE-2023-41046
Velocity execution without script right through VelocityCode and VelocityWiki property
HIGH 8.0
CVE-2023-40572
XWiki Platform vulnerable to CSRF privilege escalation/RCE via the create action
MEDIUM 6.5
CVE-2023-37911
org.xwiki.platform:xwiki-platform-oldcore may leak data through deleted and re-created documents
HIGH 8.4
CVE-2023-35157
XWiki Platform vulnerable to reflected cross-site scripting via delattachment action
MEDIUM 4.7
CVE-2023-32068
org.xwiki.platform:xwiki-platform-oldcore Open Redirect vulnerability
CRITICAL 9.9
CVE-2023-29526
XWiki Platform's async and display macro allow displaying and interacting with any document in restricted mode
CRITICAL 9.9
CVE-2023-29523
XWiki Platform vulnerable to code injection in display method used in user profiles
HIGH 7.5
CVE-2023-29208
org.xwiki.platform:xwiki-platform-oldcore vulnerable to data leak through deleted documents
MEDIUM 4.7
CVE-2023-29204
org.xwiki.platform:xwiki-platform-oldcore Open Redirect vulnerability
CRITICAL 9.9
CVE-2023-26474
XWiki Platform vulnerable to privilege escalation via properties with wiki syntax that are executed with wrong author
MEDIUM 5.7
CVE-2023-26470
XWiki Platform subject to Uncontrolled Resource Consumption
HIGH 7.5
CVE-2022-41932
Creation of new database tables through login form on PostgreSQL
MEDIUM 4.9
CVE-2022-41929
Missing Authorization in User#setDisabledStatus in org.xwiki.platform:xwiki-platform-oldcore
HIGH 7.5
CVE-2022-36092
XWiki Platform Old Core vulnerable to Authentication Bypass Using the Login Action
HIGH 8.1
CVE-2022-36090
XWiki Platform Improper Authorization check for inactive users
HIGH 8.1
CVE-2022-31166
XWiki.WebHome vulnerable to Improper Privilege Management in XWiki resolving groups
LOW 2.7
CVE-2022-29253
Path Traversal in XWiki Platform
MEDIUM 5.5
CVE-2022-23621
Missing authorization in xwiki-platform
MEDIUM 4.7
CVE-2022-23618
URL Redirection to Untrusted Site ('Open Redirect')
MEDIUM 6.5
CVE-2022-23617
Missing authorization in xwiki-platform
MEDIUM 5.4
CVE-2022-23615
Partial authorization bypass on document save in xwiki-platform
Ready to move
Start Securing
Free, no credit card | First findings in minutes