XWiki Platform是XWiki开源的一套用于创建Web协作应用程序的Wiki平台。 XWiki Platform 10.9至16.4.6版本、16.5.0-rc-1至16.10.2版本和17.0.0-rc-1版本存在安全漏洞,该漏洞源于REST API可访问页面标题,可能导致信息泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| xwiki | xwiki-platform | >= 10.9, < 16.4.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-49587 | XWiki does not require right warnings for notification displayer objects | |
| CVE-2025-49586 | XWiki allows remote code execution through preview of XClass changes in AWM editor | |
| CVE-2025-49585 | XWiki does not require right warnings for XClass definitions | |
| CVE-2025-49583 | XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRenderer | |
| CVE-2025-49582 | XWiki's required right warnings for macros are incomplete | |
| CVE-2025-49581 | XWiki allows remote code execution through default value of wiki macro wiki-type parameter | |
| CVE-2025-49580 | XWiki allows privilege escalation through link refactoring |
No comments yet