XWiki Platform是XWiki开源的一套用于创建Web协作应用程序的Wiki平台。 XWiki Platform 17.3.0及之前版本存在安全漏洞,该漏洞源于输入中和不当,可能导致存储型跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | XWiki through version 17.3.0 contains stored cross-site scripting caused by improper sanitization of inputs in the Administration interface's Presentation section, letting authenticated administrators inject JavaScript that executes in visitors' browsers, exploit requires administrator authentication. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-51990.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-9235 | 3.5 LOW | Scada-LTS compound_events.shtm cross site scripting |
| CVE-2025-9234 | 3.5 LOW | Scada-LTS maintenance_events.shtm cross site scripting |
| CVE-2025-9233 | 3.5 LOW | Scada-LTS view_edit.shtm cross site scripting |
| CVE-2025-50864 | elysiajs-cors 安全漏洞 | |
| CVE-2024-53495 | my-site 安全漏洞 | |
| CVE-2024-50640 | Jeewx-Boot 安全漏洞 | |
| CVE-2024-57157 | Jantent 安全漏洞 | |
| CVE-2024-57491 | jobx 安全漏洞 | |
| CVE-2024-57152 | my-site 安全漏洞 | |
| CVE-2024-57155 | Radar 安全漏洞 | |
| CVE-2024-57154 | dts-mall 安全漏洞 | |
| CVE-2025-51991 | XWiki Platform 安全漏洞 | |
| CVE-2025-28041 | iTranswarp 安全漏洞 | |
| CVE-2025-50902 | Open-Shop 安全漏洞 | |
| CVE-2025-50901 | JeeWMS 安全漏洞 | |
| CVE-2025-50904 | my-site 安全漏洞 | |
| CVE-2025-50503 | Touch Lebanon Mobile App 安全漏洞 | |
| CVE-2025-55499 | Tenda AC6 安全漏洞 | |
| CVE-2025-55444 | Online Artwork and Fine Arts 安全漏洞 | |
| CVE-2025-55498 | Tenda AC6 安全漏洞 |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet