Vulnerabilities
Vulnerable Software
Xwiki:  >> Xwiki  >> 14.9  Security Vulnerabilities
XWiki Platform is a generic wiki platform. Starting in version 13.10, it's possible to use the right of an existing document content author to execute a text area property. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11. There are no known workarounds.
CVSS Score
9.9
EPSS Score
0.004
Published
2023-03-02
XWiki Platform is a generic wiki platform. Starting in version 2.3-milestone-1, the annotation displayer does not execute the content in a restricted context. This allows executing anything with the right of the author of any document by annotating the document. This has been patched in XWiki 13.10.11, 14.4.7 and 14.10. There is no easy workaround except to upgrade.
CVSS Score
9.9
EPSS Score
0.294
Published
2023-03-02
XWiki Platform is a generic wiki platform. Starting in version 12.10, a user without script rights can introduce a stored cross-site scripting by using the Live Data macro. This has been patched in XWiki 14.9, 14.4.7, and 13.10.10. There are no known workarounds.
CVSS Score
8.9
EPSS Score
0.012
Published
2023-03-02


Contact Us

Shodan ® - All rights reserved