23 Total advisories
23 Vulnerabilities
0 Malware
Vulnerabilities
MEDIUM 6.1
CVE-2026-40105
XWiki has Reflected Cross-Site Scripting (XSS) in page history compare
HIGH 7.5
CVE-2022-36091
XWiki Platform Web Templates vulnerable to Missing Authorization, Exposure of Private Personal Information to Unauthorized Actor
UNKNOWN
CVE-2026-24128
XWiki Affected by Reflected Cross-Site Scripting (XSS) in Error Messages
UNKNOWN
CVE-2025-66472
XWiki vulnerable to a reflected XSS via xredirect parameter in DeleteApplication
UNKNOWN
CVE-2025-32430
XWiki allows Reflected XSS in two templates
CRITICAL 9.0
CVE-2024-43401
In XWiki Platform, payloads stored in content is executed when a user with script/programming right edit them
CRITICAL 9.0
CVE-2024-41947
XWiki Platform vulnerable to Cross-Site Scripting (XSS) through conflict resolution
CRITICAL 9.0
CVE-2023-45137
XWiki Platform vulnerable to XSS with edit right in the create document form for existing pages
CRITICAL 9.6
CVE-2023-45136
XWiki Platform web templates vulnerable to reflected XSS in the create document form if name validation is enabled
CRITICAL 9.0
CVE-2023-45135
XWiki users can be tricked to execute scripts as the create page action doesn't display the page's title
CRITICAL 9.0
CVE-2023-45134
XWiki Platform XSS vulnerability from account in the create page form via template provider
MEDIUM 5.4
CVE-2023-40176
XWiki Platform Stored Cross-site Scripting in the user profile via the timezone displayer
CRITICAL 9.6
CVE-2023-35160
XWiki Platform vulnerable to reflected cross-site scripting via back and xcontinue parameters in resubmit template
CRITICAL 9.6
CVE-2023-35159
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in deletespace template
CRITICAL 9.0
CVE-2023-34464
XWiki vulnerable to stored cross-site scripting via any wiki document and the displaycontent/rendercontent template
MEDIUM 5.0
CVE-2023-29513
xwiki-platform-web-templates allows users to be created even when registration is disabled without validation via template macro
CRITICAL 9.9
CVE-2023-29512
xwiki-platform-web-templates vulnerable to Eval Injection
HIGH 8.9
CVE-2023-29207
Improper Neutralization of Script-Related HTML Tags (XSS) in the LiveTable Macro
LOW 3.7
CVE-2023-29203
Unauthenticated user can have information about hidden users on subwikis through uorgsuggest.vm
MEDIUM 4.3
CVE-2022-36095
XWiki Cross-Site Request Forgery (CSRF) for actions on tags
HIGH 8.5
CVE-2022-36093
XWiki Platform Web Templates vulnerable to Unauthorized User Registration Through the Distribution Wizard
MEDIUM 5.3
CVE-2022-24819
Unauthenticated user can retrieve the list of users through uorgsuggest.vm
HIGH 7.4
CVE-2022-23622
Cross site scripting in registration template in xwiki-platform
Ready to move
Start Securing
Free, no credit card | First findings in minutes