maven

org.xwiki.platform:xwiki-platform-oldcore

View on maven registry
46 Total advisories
46 Vulnerabilities
0 Malware

Vulnerabilities

CRITICAL 9.6
Maven

CVE-2021-29459

XSS Cross Site Scripting

HIGH 8.5
Maven

CVE-2020-15252

RCE in XWiki

MEDIUM 4.1
Maven

CVE-2021-43841

Cross-site Scripting by SVG upload in xwiki-platform

MEDIUM 6.6
Maven

CVE-2020-15171

Users with SCRIPT right can execute arbitrary code in XWiki

UNKNOWN
Maven

CVE-2026-34151

XWiki Platform Old Core: Resource path traversal via /skin/ action endpoint in Jetty 12+

HIGH 8.2
Maven

CVE-2026-40104

XWiki's REST APIs can list all pages/spaces, leading to unavailability

UNKNOWN
Maven

CVE-2026-33229

XWiki vulnerable to remote code execution with script right through unprotected Velocity scripting API

CRITICAL 9.9
Maven

CVE-2023-36468

Upgrading doesn't prevent exploiting vulnerable XWiki documents

UNKNOWN
Maven

CVE-2024-56158

XWiki allows SQL injection in query endpoint of REST API with Oracle

UNKNOWN
Maven

CVE-2025-54125

XWiki exposes passwords and emails stored in fields not named password/email in xml.vm

UNKNOWN
Maven

CVE-2025-54124

XWiki leaks password hashes and other accessible password properties

UNKNOWN
Maven

CVE-2025-54385

XWiki Platform vulnerable to SQL injection through XWiki#searchDocuments API

UNKNOWN
Maven

CVE-2025-49586

XWiki allows remote code execution through preview of XClass changes in AWM editor

UNKNOWN
Maven

CVE-2025-32968

org.xwiki.platform:xwiki-platform-oldcore allows SQL injection in short form select requests through the script query API

CRITICAL 9.1
Maven

CVE-2023-29507

org.xwiki.platform:xwiki-platform-oldcore makes Incorrect Use of Privileged APIs with DocumentAuthors

CRITICAL 9.0
Maven

CVE-2024-37899

XWiki Platform allows remote code execution from user account

CRITICAL 9.0
Maven

CVE-2024-43400

XWiki Platform allows XSS through XClass name in string properties

MEDIUM 4.3
Maven

CVE-2024-37898

XWiki Platform vulnerable to document deletion and overwrite from edit

CRITICAL 9.9
Maven

CVE-2024-31987

XWiki Platform remote code execution from account via custom skins support

CRITICAL 9.9
Maven

CVE-2024-31981

XWiki Platform: Privilege escalation (PR) from user registration through PDFClass

MEDIUM 6.8
Maven

CVE-2024-31464

XWiki Platform: Password hash might be leaked by diff once the xobject holding them is deleted

UNKNOWN
Maven

CVE-2006-7223

XWiki Remote Code Execution

HIGH 8.0
Maven

CVE-2024-21648

XWiki has no right protection on rollback action

HIGH 8.8
Maven

CVE-2023-46243

XWiki Platform vulnerable to privilege escalation and remote code execution via the edit action

CRITICAL 9.6
Maven

CVE-2023-46242

XWiki Platform vulnerable to remote code execution via the edit action because it lacks CSRF token

MEDIUM 6.3
Maven

CVE-2023-41046

Velocity execution without script right through VelocityCode and VelocityWiki property

HIGH 8.0
Maven

CVE-2023-40572

XWiki Platform vulnerable to CSRF privilege escalation/RCE via the create action

MEDIUM 6.5
Maven

CVE-2023-37911

org.xwiki.platform:xwiki-platform-oldcore may leak data through deleted and re-created documents

HIGH 8.4
Maven

CVE-2023-35157

XWiki Platform vulnerable to reflected cross-site scripting via delattachment action

MEDIUM 4.7
Maven

CVE-2023-32068

org.xwiki.platform:xwiki-platform-oldcore Open Redirect vulnerability

CRITICAL 9.9
Maven

CVE-2023-29526

XWiki Platform's async and display macro allow displaying and interacting with any document in restricted mode

CRITICAL 9.9
Maven

CVE-2023-29523

XWiki Platform vulnerable to code injection in display method used in user profiles

HIGH 7.5
Maven

CVE-2023-29208

org.xwiki.platform:xwiki-platform-oldcore vulnerable to data leak through deleted documents

MEDIUM 4.7
Maven

CVE-2023-29204

org.xwiki.platform:xwiki-platform-oldcore Open Redirect vulnerability

CRITICAL 9.9
Maven

CVE-2023-26474

XWiki Platform vulnerable to privilege escalation via properties with wiki syntax that are executed with wrong author

MEDIUM 5.7
Maven

CVE-2023-26470

XWiki Platform subject to Uncontrolled Resource Consumption

HIGH 7.5
Maven

CVE-2022-41932

Creation of new database tables through login form on PostgreSQL

MEDIUM 4.9
Maven

CVE-2022-41929

Missing Authorization in User#setDisabledStatus in org.xwiki.platform:xwiki-platform-oldcore

HIGH 7.5
Maven

CVE-2022-36092

XWiki Platform Old Core vulnerable to Authentication Bypass Using the Login Action

HIGH 8.1
Maven

CVE-2022-36090

XWiki Platform Improper Authorization check for inactive users

HIGH 8.1
Maven

CVE-2022-31166

XWiki.WebHome vulnerable to Improper Privilege Management in XWiki resolving groups

LOW 2.7
Maven

CVE-2022-29253

Path Traversal in XWiki Platform

MEDIUM 5.5
Maven

CVE-2022-23621

Missing authorization in xwiki-platform

MEDIUM 4.7
Maven

CVE-2022-23618

URL Redirection to Untrusted Site ('Open Redirect')

MEDIUM 6.5
Maven

CVE-2022-23617

Missing authorization in xwiki-platform

MEDIUM 5.4
Maven

CVE-2022-23615

Partial authorization bypass on document save in xwiki-platform

Ready to move

Start Securing

Free, no credit card | First findings in minutes