Dependency scanning
Check whether org.xwiki.platform:xwiki-platform-oldcore is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2021-29459
XSS Cross Site Scripting
CVE-2020-15252
RCE in XWiki
CVE-2021-43841
Cross-site Scripting by SVG upload in xwiki-platform
CVE-2020-15171
Users with SCRIPT right can execute arbitrary code in XWiki
CVE-2026-34151
XWiki Platform Old Core: Resource path traversal via /skin/ action endpoint in Jetty 12+
CVE-2026-40104
XWiki's REST APIs can list all pages/spaces, leading to unavailability
CVE-2026-33229
XWiki vulnerable to remote code execution with script right through unprotected Velocity scripting API
CVE-2023-36468
Upgrading doesn't prevent exploiting vulnerable XWiki documents
CVE-2024-56158
XWiki allows SQL injection in query endpoint of REST API with Oracle
CVE-2025-54125
XWiki exposes passwords and emails stored in fields not named password/email in xml.vm
CVE-2025-54124
XWiki leaks password hashes and other accessible password properties
CVE-2025-54385
XWiki Platform vulnerable to SQL injection through XWiki#searchDocuments API
CVE-2025-49586
XWiki allows remote code execution through preview of XClass changes in AWM editor
CVE-2025-32968
org.xwiki.platform:xwiki-platform-oldcore allows SQL injection in short form select requests through the script query API
CVE-2023-29507
org.xwiki.platform:xwiki-platform-oldcore makes Incorrect Use of Privileged APIs with DocumentAuthors
CVE-2024-37899
XWiki Platform allows remote code execution from user account
CVE-2024-43400
XWiki Platform allows XSS through XClass name in string properties
CVE-2024-37898
XWiki Platform vulnerable to document deletion and overwrite from edit
CVE-2024-31987
XWiki Platform remote code execution from account via custom skins support
CVE-2024-31981
XWiki Platform: Privilege escalation (PR) from user registration through PDFClass
CVE-2024-31464
XWiki Platform: Password hash might be leaked by diff once the xobject holding them is deleted
CVE-2006-7223
XWiki Remote Code Execution
CVE-2024-21648
XWiki has no right protection on rollback action
CVE-2023-46243
XWiki Platform vulnerable to privilege escalation and remote code execution via the edit action
CVE-2023-46242
XWiki Platform vulnerable to remote code execution via the edit action because it lacks CSRF token
CVE-2023-41046
Velocity execution without script right through VelocityCode and VelocityWiki property
CVE-2023-40572
XWiki Platform vulnerable to CSRF privilege escalation/RCE via the create action
CVE-2023-37911
org.xwiki.platform:xwiki-platform-oldcore may leak data through deleted and re-created documents
CVE-2023-35157
XWiki Platform vulnerable to reflected cross-site scripting via delattachment action
CVE-2023-32068
org.xwiki.platform:xwiki-platform-oldcore Open Redirect vulnerability
CVE-2023-29526
XWiki Platform's async and display macro allow displaying and interacting with any document in restricted mode
CVE-2023-29523
XWiki Platform vulnerable to code injection in display method used in user profiles
CVE-2023-29208
org.xwiki.platform:xwiki-platform-oldcore vulnerable to data leak through deleted documents
CVE-2023-29204
org.xwiki.platform:xwiki-platform-oldcore Open Redirect vulnerability
CVE-2023-26474
XWiki Platform vulnerable to privilege escalation via properties with wiki syntax that are executed with wrong author
CVE-2023-26470
XWiki Platform subject to Uncontrolled Resource Consumption
CVE-2022-41932
Creation of new database tables through login form on PostgreSQL
CVE-2022-41929
Missing Authorization in User#setDisabledStatus in org.xwiki.platform:xwiki-platform-oldcore
CVE-2022-36092
XWiki Platform Old Core vulnerable to Authentication Bypass Using the Login Action
CVE-2022-36090
XWiki Platform Improper Authorization check for inactive users
CVE-2022-31166
XWiki.WebHome vulnerable to Improper Privilege Management in XWiki resolving groups
CVE-2022-29253
Path Traversal in XWiki Platform
CVE-2022-23621
Missing authorization in xwiki-platform
CVE-2022-23618
URL Redirection to Untrusted Site ('Open Redirect')
CVE-2022-23617
Missing authorization in xwiki-platform
CVE-2022-23615
Partial authorization bypass on document save in xwiki-platform
Browse more Maven advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes