org.xwiki.rendering:xwiki-rendering-xml
Maven3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.xwiki.rendering:xwiki-rendering-xmlpage 1 of 1
- CVE-2023-37908CRITICALCVSS 9.0EG 9.0fixed in 14.10.42023-10-25
vulnerable: 14.10 ... 14.9-rc-1 (12 versions)
XWiki Rendering is a generic Rendering system that converts textual input in a given syntax into another syntax. The cleaning of attributes during XHTML rendering, introduced in version 14.6-rc-1, allowed the injection of arbitrary HTML co…
- CVE-2025-53837CRITICALCVSS 9.9EG 9.9fixed in 14.10.22026-09-18
vulnerable: 10.0 ... 9.9-rc-2 (353 versions)
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile or …
- CVE-2025-66474HIGHCVSS 8.8EG 8.8fixed in 16.10.10, 17.4.3 or 17.6.0-rc-1, by version range2025-12-10
vulnerable: 17.5.0
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Versions 16.10.9 and below, 17.0.0-rc-1 through 17.4.2 and 17.5.0-rc-1 through 17.5.0 ha…
Check whether org.xwiki.rendering:xwiki-rendering-xml is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.xwiki.rendering:xwiki-rendering-xml CVEs against the assets you own.
Book a Demo →