Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

xwiki — Vulnerabilities & Security Advisories 247

Browse all 247 CVE security advisories affecting xwiki. AI-powered Chinese analysis, POCs, and references for each vulnerability.

XWiki serves as an open-source enterprise wiki platform, enabling organizations to create, manage, and share collaborative documentation and knowledge bases. Its architecture, built on Java and supporting complex extensions, has historically exposed it to a wide array of security flaws, resulting in 243 recorded Common Vulnerabilities and Exposures. The most prevalent issues involve Remote Code Execution (RCE), Cross-Site Scripting (XSS), and privilege escalation vulnerabilities, often stemming from improper input validation or insecure default configurations. Notable incidents have included attackers exploiting unpatched RCE flaws to gain full system control, highlighting the risks associated with its extensive plugin ecosystem. While the project maintains an active security response team, the sheer volume of disclosed defects underscores the complexity of securing a feature-rich, Java-based application. Continuous patching and strict access controls remain essential for mitigating these persistent threats in production environments.

Found 230 results / 247 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-48048 XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests — xwiki-platform CWE-359 7.5 High 2026-08-10
CVE-2026-48047 XWiki Platform vulnerable to potential arbitrary file writing using path traversal from (subwiki) admin — xwiki-platform CWE-24 5.9 Medium 2026-08-07
CVE-2026-33137 XWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName} — xwiki-platform CWE-862 - - 2026-05-20
CVE-2026-40105 XWiki has Reflected Cross-Site Scripting (XSS) in its page history compare functionality — xwiki-platform CWE-80 8.8 - 2026-04-15
CVE-2026-33229 XWiki Platform affected by remote code execution with script right through unprotected Velocity scripting API — xwiki-platform CWE-862 9.9AI Critical AI 2026-04-08
CVE-2026-26000 XWiki Platform affected by click-jacking through CSS injection in comments — xwiki-platform CWE-1021 4.1AI Medium AI 2026-02-12
CVE-2026-24128 XWiki Affected by Reflected Cross-Site Scripting (XSS) in Error Messages — xwiki-platform CWE-79 9.6 - 2026-01-23
CVE-2025-66473 XWiki's REST APIs don't enforce any limits, leading to unavailability and OOM in large wikis — xwiki-platform CWE-770 7.5AI High AI 2025-12-10
CVE-2025-66472 XWiki vulnerable to a reflected XSS via xredirect parameter in DeleteApplication — xwiki-platform CWE-79 6.1AI Medium AI 2025-12-10
CVE-2025-55749 The XWiki Jetty package (XJetty) allows accessing any application file through URL — xwiki-platform CWE-284 7.5AI High AI 2025-12-01
CVE-2025-52472 XWiki Platform vulnerable to HQL injection via wiki and space search REST API — xwiki-platform CWE-89 7.1AI High AI 2025-10-06
CVE-2025-55748 XWiki Platform's configuration files can be accessed through jsx and sx endpoints — xwiki-platform CWE-23 7.5AI High AI 2025-09-03
CVE-2025-55747 XWiki Platform's configuration files can be accessed through the webjars API — xwiki-platform CWE-23 7.5AI High AI 2025-09-03
CVE-2025-58049 XWiki PDF export jobs store sensitive cookies unencrypted in job statuses — xwiki-platform CWE-212 5.8 Medium 2025-08-28
CVE-2025-54125 XWiki Platform: Password and email exposure in xml.vm fields — xwiki-platform CWE-359 8.1AI High AI 2025-08-05
CVE-2025-54124 XWiki Platform: Any user with editing rights can access password properties through Database List Properties — xwiki-platform CWE-359 6.5AI Medium AI 2025-08-05
CVE-2025-32430 XWiki Platform contains Reflected XSS vulnerability in two templates — xwiki-platform CWE-79 6.1AI Medium AI 2025-08-05
CVE-2025-54385 XWiki Platform's searchDocuments API allows for SQL injection — xwiki-platform CWE-20 8.8 - 2025-07-26
CVE-2025-32429 XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter — xwiki-platform CWE-89 9.8 - 2025-07-24
CVE-2025-49587 XWiki does not require right warnings for notification displayer objects — xwiki-platform CWE-357 5.4AI Medium AI 2025-06-13
CVE-2025-49586 XWiki allows remote code execution through preview of XClass changes in AWM editor — xwiki-platform CWE-863 8.8AI High AI 2025-06-13
CVE-2025-49585 XWiki does not require right warnings for XClass definitions — xwiki-platform CWE-357 6.3AI Medium AI 2025-06-13
CVE-2025-49584 XWiki makes title of inaccessible pages available through the class property values REST API — xwiki-platform CWE-201 5.3AI Medium AI 2025-06-13
CVE-2025-49583 XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin right — xwiki-platform CWE-270 4.6AI Medium AI 2025-06-13
CVE-2025-49582 XWiki's required right warnings for macros are incomplete — xwiki-platform CWE-357 5.4AI Medium AI 2025-06-13
CVE-2025-49581 XWiki allows remote code execution through default value of wiki macro wiki-type parameters — xwiki-platform CWE-94 8.8AI High AI 2025-06-13
CVE-2025-49580 XWiki allows privilege escalation through link refactoring — xwiki-platform CWE-266 9.3AI Critical AI 2025-06-13
CVE-2024-56158 XWiki allows SQL injection in query endpoint of REST API with Oracle — xwiki-platform CWE-89 9.8AI Critical AI 2025-06-12
CVE-2025-48063 XWiki Platform Security Authorization Bridge allows users with just edit right can enforce required rights with programming right — xwiki-platform CWE-285 7.1AI High AI 2025-05-21
CVE-2025-46554 XWiki missing authorization when accessing the wiki level attachments list and metadata via REST API — xwiki-platform CWE-862 5.3 Medium 2025-04-30

This page lists every published CVE security advisory associated with xwiki. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.