org.xwiki.platform:xwiki-platform-web-templates
Maven23 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.xwiki.platform:xwiki-platform-web-templatespage 1 of 1
- CVE-2022-23622HIGHCVSS 7.4EG 7.4fixed in 12.10.11, 13.4.7 or 13.10.3, by version range2022-02-09
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions there is a cross site scripting (XSS) vector in the `registerinline.vm` template related to the `xredirect` hidde…
- CVE-2022-24819MEDIUMCVSS 5.3EG 5.3fixed in 12.10.11, 13.4.4 or 13.9, by version range2022-04-08
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A guest user without the right to view pages of the wiki can still list documents related to users of the wiki. The problem has been p…
- CVE-2022-36091HIGHCVSS 7.5EG 7.5fixed in 13.10.42022-09-08
XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. Through the suggestion feature, string and list properties of objects the user shouldn't have access to can be accessed in versions prior to 13.10.4 an…
- CVE-2022-36093HIGHCVSS 8.5EG 8.5fixed in 13.10.5 or 14.3-rc-1, by version range2022-09-08
XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform. By passing a template of the distribution wizard to the xpart template, user accounts can be created even when user registration is disabled. This also…
- CVE-2022-36095MEDIUMCVSS 4.3EG 4.3fixed in 13.10.5 or 14.3, by version range2022-09-08
XWiki Platform is a generic wiki platform. Prior to versions 13.10.5 and 14.3, it is possible to perform a Cross-Site Request Forgery (CSRF) attack for adding or removing tags on XWiki pages. The problem has been patched in XWiki 13.10.5 a…
- CVE-2023-29203LOWCVSS 3.7EG 3.7fixed in 13.10.8, 14.4.3 or 14.7-rc-1, by version range2023-04-15
XWiki Commons are technical libraries common to several other top level XWiki projects. It's possible to list some users who are normally not viewable from subwiki by requesting users on a subwiki which allows only global users with `uorgs…
- CVE-2023-29207HIGHCVSS 8.9EG 8.9fixed in 13.10.10, 14.4.6 or 14.9, by version range2023-04-15
XWiki Commons are technical libraries common to several other top level XWiki projects. The Livetable Macro wasn't properly sanitizing column names, thus allowing the insertion of raw HTML code including JavaScript. This vulnerability was…
- CVE-2023-29512CRITICALCVSS 9.9EG 9.9fixed in 13.10.11, 14.4.8 or 14.10.1, by version range2023-04-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on a page (e.g., it's own user page), can execute arbitrary Groovy, Python or Velocity code in XWiki leading…
- CVE-2023-29513MEDIUMCVSS 5.0EG 5.0fixed in 14.10.12023-04-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. If guest has view right on any document. It's possible to create a new user using the `distribution/firstadminuser.wiki` in the wrong …
- CVE-2023-34464CRITICALCVSS 9.0EG 9.0fixed in 14.4.8, 14.10.5 or 15.1-rc-1, by version range2023-06-23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.2.1 until versions 14.4.8, 14.10.5, and 15.1RC1 of org.xwiki.platform:xwiki-platform-web and any version prior t…
- CVE-2023-35159CRITICALCVSS 9.6EG 9.6fixed in 14.10.5 or 15.1-rc-1, by version range2023-06-23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the deletespac…
- CVE-2023-35160CRITICALCVSS 9.6EG 9.6fixed in 14.10.5 or 15.1-rc-1, by version range2023-06-23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Users are able to forge an URL with a payload allowing to inject Javascript in the page (XSS). It's possible to exploit the resubmit t…
- CVE-2023-40176CRITICALCVSS 9.0EG 9.0fixed in 14.10.52023-08-23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can exploit a stored XSS through their user profile by setting the payload as the value of the time zone user pref…
- CVE-2023-45134CRITICALCVSS 9.0EG 9.0fixed in 14.10.12 or 15.5-rc-1, by version range2023-10-25
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. `org.xwiki.platform:xwiki-platform-web` starting in version 3.1-milestone-1 and prior to 13.4-rc-1, `org.xwiki.platform:xwiki-platform…
- CVE-2023-45135HIGHCVSS 8.0EG 8.0fixed in 14.10.12 or 15.5-rc-1, by version range2023-10-25
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In `org.xwiki.platform:xwiki-platform-web` versions 7.2-milestone-2 until 14.10.12 and `org.xwiki.platform:xwiki-platform-web-template…
- CVE-2023-45136CRITICALCVSS 9.6EG 9.6fixed in 14.10.12 or 15.5-rc-1, by version range2023-10-25
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When document names are validated according to a name strategy (disabled by default), XWiki starting in version 12.0-rc-1 and prior to…
- CVE-2023-45137MEDIUMCVSS 5.4EG 5.4fixed in 14.10.12 or 15.5-rc-1, by version range2023-10-25
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. `org.xwiki.platform:xwiki-platform-web` starting in version 3.1-milestone-2 and prior to version 13.4-rc-1, as well as `org.xwiki.plat…
- CVE-2024-41947CRITICALCVSS 9.0EG 9.0fixed in 15.10.8 or 16.3.0-rc-1, by version range2024-07-31
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. By creating a conflict when another user with more rights is currently editing a page, it is possible to execute JavaScript snippets o…
- CVE-2024-43401CRITICALCVSS 9.0EG 9.0fixed in 15.10-rc-12024-08-19
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A user without script/programming right can trick a user with elevated rights to edit a content with a malicious payload using a WYSIW…
- CVE-2025-32430MEDIUMCVSS 6.1EG 6.1fixed in 16.4.8, 16.10.6 or 17.3.0-rc-1, by version range2025-08-06
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-3 through 16.4.7, 16.5.0-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, two templates contain reflecte…
- CVE-2025-66472MEDIUMCVSS 6.1EG 6.1fixed in 16.10.10 or 17.4.2, by version range2025-12-10
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 6.2-milestone-1 through 16.10.9 and 17.0.0-rc-1 through 17.4.1 of both XWiki Platform Flamingo Skin Resources and XWiki Plat…
- CVE-2026-24128MEDIUMCVSS 6.1EG 6.1fixed in 16.10.12, 17.4.5 or 17.8.0-rc-1, by version range2026-01-24
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 7.0-milestone-2 through 16.10.11, 17.0.0-rc-1 through 17.4.4, and 17.5.0-rc-1 through 17.7.0 contain a reflected Cross-site S…
- CVE-2026-40105MEDIUMCVSS 6.1EG 6.1fixed in 16.10.16, 17.4.8 or 17.10.1, by version range2026-04-15
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 10.4-rc-1, through 16.10.15, 17.0.0-rc-1, through 17.4.7 and 17.5.0-rc-1 through 17.10.0 contain a reflected cross-site scri…
Check whether org.xwiki.platform:xwiki-platform-web-templates is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.xwiki.platform:xwiki-platform-web-templates CVEs against the assets you own.
Book a Demo →