Exposición de XWiki

Wikis
328
score de exposición
37
sitios usan
1
en explotación
121
críticos
Análisis Vexday

Com 245 CVEs catalogadas, o XWiki apresenta um volume expressivo de vulnerabilidades, sendo 121 delas de severidade crítica — número que por si só justifica atenção redobrada em ambientes que utilizam a plataforma. A falha mais comum é CWE-79 (Cross-Site Scripting), padrão que, em wikis colaborativos com renderização de conteúdo rico, tende a ter superfície de ataque ampla e impacto relevante sobre usuários autenticados. A CVE mais perigosa atualmente ativa é CVE-2025-24893, com score EPSS de 0,999 — valor que indica probabilidade extremamente alta de exploração ativa —, exigindo priorização imediata de remediação. A taxa de exploração confirmada no CISA KEV está em linha com a média geral do catálogo, mas o EPSS elevado dessa CVE sugere que a exposição real pode ser significativamente maior do que o número de entradas KEV indica.

CVEs

245 resultados
CVE-2023-45135CRITICALXWiki users can be tricked to execute scripts as the create page action doesn't display the page's titleEPSS 1.7%CVE-2023-29506MEDIUMorg.xwiki.platform:xwiki-platform-security-authentication-default XSS with authenticated endpointsEPSS 1.7%CVE-2025-55747CRITICALXWiki Platform's configuration files can be accessed through the webjars APIEPSS 1.7%CVE-2024-41947CRITICALXWiki Platform XSS through conflict resolutionEPSS 1.7%CVE-2023-37909CRITICALPrivilege escalation (PR)/remote code execution from account through Menu.UIExtensionSheetEPSS 1.6%CVE-2024-55877CRITICALXWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosListEPSS 1.6%CVE-2023-37914CRITICALPrivilege escalation (PR)/RCE from account through Invitation subject/messageEPSS 1.5%CVE-2022-24897HIGHArbitrary filesystem write access from VelocityEPSS 1.5%CVE-2023-35155HIGHXWiki Platform vulnerable to cross-site scripting in target parameter via share page by emailEPSS 1.5%CVE-2025-55749HIGHThe XWiki Jetty package (XJetty) allows accessing any application file through URLEPSS 1.5%CVE-2022-24898MEDIUMArbitrary file access through XML parsing in org.xwiki.commons:xwiki-commons-xmlEPSS 1.5%CVE-2024-31981CRITICALXWiki Platform: Privilege escalation (PR) from user registration through PDFClassEPSS 1.4%CVE-2024-31983CRITICALXWiki Platform: Remote code execution from edit in multilingual wikis via translationsEPSS 1.4%CVE-2024-31987CRITICALXWiki Platform remote code execution from account via custom skins supportEPSS 1.4%CVE-2023-29202CRITICALorg.xwiki.platform:xwiki-platform-rendering-macro-rss Cross-site Scripting vulnerabilityEPSS 1.4%CVE-2023-29207HIGHImproper Neutralization of Script-Related HTML Tags (XSS) in the LiveTable MacroEPSS 1.4%CVE-2021-21380HIGHRating Script Service expose XWiki to SQL injectionEPSS 1.3%CVE-2020-15171MEDIUMUsers with SCRIPT rights can execute arbitrary code in XWikiEPSS 1.3%CVE-2022-29251HIGHCross-site Scripting in the Flamingo theme managerEPSS 1.3%CVE-2025-54125HIGHXWiki Platform: Password and email exposure in xml.vm fieldsEPSS 1.3%