XWiki Rendering是XWiki基金会的一个通用渲染系统,它将给定语法(wiki 语法、HTML 等)中的文本输入转换为另一种语法(XHTML 等)。 XWiki Rendering 16.10.9及之前版本、17.0.0-rc-1至17.4.2版本和17.5.0-rc-1至17.5.0版本存在安全漏洞,该漏洞源于html注入保护不足,可能导致远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| xwiki | xwiki-rendering | < 16.10.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-66472 | XWiki vulnerable to a reflected XSS via xredirect parameter in DeleteApplication | |
| CVE-2025-66473 | XWiki's REST APIs don't enforce any limits, leading to unavailability and OOM in large wik |
No comments yet