Dependency scanning
Check whether org.xwiki.platform:xwiki-platform-web-templates is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-40105
XWiki has Reflected Cross-Site Scripting (XSS) in page history compare
CVE-2022-36091
XWiki Platform Web Templates vulnerable to Missing Authorization, Exposure of Private Personal Information to Unauthorized Actor
CVE-2026-24128
XWiki Affected by Reflected Cross-Site Scripting (XSS) in Error Messages
CVE-2025-66472
XWiki vulnerable to a reflected XSS via xredirect parameter in DeleteApplication
CVE-2025-32430
XWiki allows Reflected XSS in two templates
CVE-2024-43401
In XWiki Platform, payloads stored in content is executed when a user with script/programming right edit them
CVE-2024-41947
XWiki Platform vulnerable to Cross-Site Scripting (XSS) through conflict resolution
CVE-2023-45137
XWiki Platform vulnerable to XSS with edit right in the create document form for existing pages
CVE-2023-45136
XWiki Platform web templates vulnerable to reflected XSS in the create document form if name validation is enabled
CVE-2023-45135
XWiki users can be tricked to execute scripts as the create page action doesn't display the page's title
CVE-2023-45134
XWiki Platform XSS vulnerability from account in the create page form via template provider
CVE-2023-40176
XWiki Platform Stored Cross-site Scripting in the user profile via the timezone displayer
CVE-2023-35160
XWiki Platform vulnerable to reflected cross-site scripting via back and xcontinue parameters in resubmit template
CVE-2023-35159
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in deletespace template
CVE-2023-34464
XWiki vulnerable to stored cross-site scripting via any wiki document and the displaycontent/rendercontent template
CVE-2023-29513
xwiki-platform-web-templates allows users to be created even when registration is disabled without validation via template macro
CVE-2023-29512
xwiki-platform-web-templates vulnerable to Eval Injection
CVE-2023-29207
Improper Neutralization of Script-Related HTML Tags (XSS) in the LiveTable Macro
CVE-2023-29203
Unauthenticated user can have information about hidden users on subwikis through uorgsuggest.vm
CVE-2022-36095
XWiki Cross-Site Request Forgery (CSRF) for actions on tags
CVE-2022-36093
XWiki Platform Web Templates vulnerable to Unauthorized User Registration Through the Distribution Wizard
CVE-2022-24819
Unauthenticated user can retrieve the list of users through uorgsuggest.vm
CVE-2022-23622
Cross site scripting in registration template in xwiki-platform
Browse more Maven advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes