maven

org.xwiki.platform:xwiki-platform-web

View on maven registry
15 Total advisories
15 Vulnerabilities
0 Malware

Dependency scanning

Check whether org.xwiki.platform:xwiki-platform-web is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

CRITICAL 9.6
Maven

CVE-2021-29459

XSS Cross Site Scripting

MEDIUM 5.3
Maven

CVE-2021-32731

The reset password form reveal users email address

UNKNOWN
Maven

CVE-2026-26000

XWiki vulnerable to click-jacking through CSS injection in comments

HIGH 7.5
Maven

CVE-2022-36091

XWiki Platform Web Templates vulnerable to Missing Authorization, Exposure of Private Personal Information to Unauthorized Actor

HIGH 7.5
Maven

CVE-2020-13654

Improper escaping in XWiki Platform

CRITICAL 9.0
Maven

CVE-2023-45137

XWiki Platform vulnerable to XSS with edit right in the create document form for existing pages

CRITICAL 9.0
Maven

CVE-2023-45135

XWiki users can be tricked to execute scripts as the create page action doesn't display the page's title

CRITICAL 9.0
Maven

CVE-2023-45134

XWiki Platform XSS vulnerability from account in the create page form via template provider

CRITICAL 9.0
Maven

CVE-2023-34464

XWiki vulnerable to stored cross-site scripting via any wiki document and the displaycontent/rendercontent template

HIGH 8.9
Maven

CVE-2023-29207

Improper Neutralization of Script-Related HTML Tags (XSS) in the LiveTable Macro

MEDIUM 6.5
Maven

CVE-2023-26473

Unprivileged XWiki Platform users can make arbitrary select queries using DatabaseListProperty and suggest.vm

HIGH 8.9
Maven

CVE-2022-36094

XWiki Platform Web Parent POM vulnerable to XSS in the attachment history

HIGH 8.5
Maven

CVE-2022-36093

XWiki Platform Web Templates vulnerable to Unauthorized User Registration Through the Distribution Wizard

MEDIUM 5.3
Maven

CVE-2022-24820

Unauthenticated user can list hidden document from multiple velocity templates in XWiki

MEDIUM 5.3
Maven

CVE-2022-23619

Information exposure in xwiki-platform

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes