Exposición de XWiki

Wikis
328
score de exposición
37
sitios usan
1
en explotación
121
críticos
Análisis Vexday

Com 245 CVEs catalogadas, o XWiki apresenta um volume expressivo de vulnerabilidades, sendo 121 delas de severidade crítica — número que por si só justifica atenção redobrada em ambientes que utilizam a plataforma. A falha mais comum é CWE-79 (Cross-Site Scripting), padrão que, em wikis colaborativos com renderização de conteúdo rico, tende a ter superfície de ataque ampla e impacto relevante sobre usuários autenticados. A CVE mais perigosa atualmente ativa é CVE-2025-24893, com score EPSS de 0,999 — valor que indica probabilidade extremamente alta de exploração ativa —, exigindo priorização imediata de remediação. A taxa de exploração confirmada no CISA KEV está em linha com a média geral do catálogo, mas o EPSS elevado dessa CVE sugere que a exposição real pode ser significativamente maior do que o número de entradas KEV indica.

CVEs

245 resultados
CVE-2022-23619MEDIUMInformation exposure in xwiki-platformEPSS 1.1%CVE-2021-29459CRITICALXSS Cross Site ScriptingEPSS 1.1%CVE-2023-26472CRITICALXWiki Platform vulnerable to privilege escalation via async macro and IconThemeSheet from the user profileEPSS 1.1%CVE-2023-29527CRITICALCode injection from account through AWM view sheet in xwiki platformEPSS 1.1%CVE-2023-26479MEDIUMorg.xwiki.platform:xwiki-platform-rendering-parser vulnerable to Improper Handling of Exceptional ConditionsEPSS 1.1%CVE-2023-37913CRITICALorg.xwiki.platform:xwiki-platform-office-importer vulnerable to arbitrary server side file writing from account through office converterEPSS 1.1%CVE-2025-46554MEDIUMXWiki missing authorization when accessing the wiki level attachments list and metadata via REST APIEPSS 1.1%CVE-2023-37908CRITICALorg.xwiki.rendering:xwiki-rendering-xml Improper Neutralization of Invalid Characters in Identifiers in Web Pages vulnerabilityEPSS 1.1%CVE-2024-37901CRITICALXWiki Platform vulnerable to remote code execution from account via SearchSuggestConfigSheetEPSS 1.1%CVE-2023-30537CRITICALorg.xwiki.platform:xwiki-platform-flamingo-theme-ui vulnerable to privilege escalationEPSS 1.0%CVE-2023-29511CRITICALxwiki-platform-administration-ui vulnerable to privilege escalationEPSS 1.0%CVE-2024-55879CRITICALXWiki allows RCE from script right in configurable sectionsEPSS 1.0%CVE-2023-36471CRITICALHTML sanitizer allows form elements in restricted in org.xwiki.commons:xwiki-commons-xmlEPSS 1.0%CVE-2022-29253LOWPath Traversal in XWiki PlatformEPSS 1.0%CVE-2023-35152CRITICALXWiki Platform vulnerable to privilege escalation (PR) from account through like LiveTableResultsEPSS 1.0%CVE-2023-29517HIGHExposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-office-viewerEPSS 1.0%CVE-2022-23622HIGHCross site scripting in registration template in xwiki-platformEPSS 1.0%CVE-2023-40573CRITICALXWiki Platform's Groovy jobs check the wrong author, allowing remote code executionEPSS 1.0%CVE-2023-46243CRITICALCode execution via the edit action in XWiki platformEPSS 1.0%CVE-2022-24820MEDIUMUnauthenticated user can list hidden document from multiple velocity templatesEPSS 1.0%