maven

org.xwiki.platform:xwiki-platform-web-templates

View on maven registry
23 Total advisories
23 Vulnerabilities
0 Malware

Dependency scanning

Check whether org.xwiki.platform:xwiki-platform-web-templates is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 6.1
Maven

CVE-2026-40105

XWiki has Reflected Cross-Site Scripting (XSS) in page history compare

HIGH 7.5
Maven

CVE-2022-36091

XWiki Platform Web Templates vulnerable to Missing Authorization, Exposure of Private Personal Information to Unauthorized Actor

UNKNOWN
Maven

CVE-2026-24128

XWiki Affected by Reflected Cross-Site Scripting (XSS) in Error Messages

UNKNOWN
Maven

CVE-2025-66472

XWiki vulnerable to a reflected XSS via xredirect parameter in DeleteApplication

UNKNOWN
Maven

CVE-2025-32430

XWiki allows Reflected XSS in two templates

CRITICAL 9.0
Maven

CVE-2024-43401

In XWiki Platform, payloads stored in content is executed when a user with script/programming right edit them

CRITICAL 9.0
Maven

CVE-2024-41947

XWiki Platform vulnerable to Cross-Site Scripting (XSS) through conflict resolution

CRITICAL 9.0
Maven

CVE-2023-45137

XWiki Platform vulnerable to XSS with edit right in the create document form for existing pages

CRITICAL 9.6
Maven

CVE-2023-45136

XWiki Platform web templates vulnerable to reflected XSS in the create document form if name validation is enabled

CRITICAL 9.0
Maven

CVE-2023-45135

XWiki users can be tricked to execute scripts as the create page action doesn't display the page's title

CRITICAL 9.0
Maven

CVE-2023-45134

XWiki Platform XSS vulnerability from account in the create page form via template provider

MEDIUM 5.4
Maven

CVE-2023-40176

XWiki Platform Stored Cross-site Scripting in the user profile via the timezone displayer

CRITICAL 9.6
Maven

CVE-2023-35160

XWiki Platform vulnerable to reflected cross-site scripting via back and xcontinue parameters in resubmit template

CRITICAL 9.6
Maven

CVE-2023-35159

XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in deletespace template

CRITICAL 9.0
Maven

CVE-2023-34464

XWiki vulnerable to stored cross-site scripting via any wiki document and the displaycontent/rendercontent template

MEDIUM 5.0
Maven

CVE-2023-29513

xwiki-platform-web-templates allows users to be created even when registration is disabled without validation via template macro

CRITICAL 9.9
Maven

CVE-2023-29512

xwiki-platform-web-templates vulnerable to Eval Injection

HIGH 8.9
Maven

CVE-2023-29207

Improper Neutralization of Script-Related HTML Tags (XSS) in the LiveTable Macro

LOW 3.7
Maven

CVE-2023-29203

Unauthenticated user can have information about hidden users on subwikis through uorgsuggest.vm

MEDIUM 4.3
Maven

CVE-2022-36095

XWiki Cross-Site Request Forgery (CSRF) for actions on tags

HIGH 8.5
Maven

CVE-2022-36093

XWiki Platform Web Templates vulnerable to Unauthorized User Registration Through the Distribution Wizard

MEDIUM 5.3
Maven

CVE-2022-24819

Unauthenticated user can retrieve the list of users through uorgsuggest.vm

HIGH 7.4
Maven

CVE-2022-23622

Cross site scripting in registration template in xwiki-platform

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes