Exposición de XWiki

Wikis
328
score de exposición
37
sitios usan
1
en explotación
121
críticos
Análisis Vexday

Com 245 CVEs catalogadas, o XWiki apresenta um volume expressivo de vulnerabilidades, sendo 121 delas de severidade crítica — número que por si só justifica atenção redobrada em ambientes que utilizam a plataforma. A falha mais comum é CWE-79 (Cross-Site Scripting), padrão que, em wikis colaborativos com renderização de conteúdo rico, tende a ter superfície de ataque ampla e impacto relevante sobre usuários autenticados. A CVE mais perigosa atualmente ativa é CVE-2025-24893, com score EPSS de 0,999 — valor que indica probabilidade extremamente alta de exploração ativa —, exigindo priorização imediata de remediação. A taxa de exploração confirmada no CISA KEV está em linha com a média geral do catálogo, mas o EPSS elevado dessa CVE sugere que a exposição real pode ser significativamente maior do que o número de entradas KEV indica.

CVEs

245 resultados
CVE-2023-40177CRITICALXWiki Platform privilege escalation (PR) from account through AWM content fieldsEPSS 1.0%CVE-2022-41928CRITICALXWiki Platform vulnerable to Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in AttachmentSelector.xmlEPSS 1.0%CVE-2021-32732HIGHCross-Site Request Forgery in xwiki-platformEPSS 1.0%CVE-2023-34467HIGHXWiki Platform may retrieve email addresses of all users EPSS 1.0%CVE-2022-23620MEDIUMPath traversal in xwiki-platform-skin-skinxEPSS 1.0%CVE-2022-23617MEDIUMMissing authorization in xwiki-platformEPSS 0.9%CVE-2023-29206CRITICALorg.xwiki.platform:xwiki-platform-skin-skinx vulnerable to basic Cross-site Scripting by exploiting JSX or SSX pluginsEPSS 0.9%CVE-2022-29258HIGHCross-site Scripting in Filter Stream Converter Application in XWiki PlatformEPSS 0.9%CVE-2022-29252HIGHCross-site Scripting in XWiki Platform Wiki UI Main WikiEPSS 0.9%CVE-2022-23621MEDIUMMissing authorization in xwiki-platformEPSS 0.9%CVE-2023-29208HIGHData leak through deleted documents EPSS 0.9%CVE-2023-26471CRITICALXWiki Platform users may execute anything with superadmin right through comments and async macroEPSS 0.9%CVE-2022-36090HIGHorg.xwiki.platform:xwiki-platform-oldcore Improper Authorization check for inactive usersEPSS 0.9%CVE-2025-66474HIGHXWiki vulnerable to remote code execution through insufficient protection against {{/html}} injectionEPSS 0.9%CVE-2025-29925HIGHXWiki allows unregistered users to access private pages information through REST endpointEPSS 0.9%CVE-2023-36477CRITICALPersistent Cross-site Scripting (XSS) through CKEditor Configuration pages in XWiki PlatformEPSS 0.9%CVE-2023-29507CRITICALorg.xwiki.platform:xwiki-platform-oldcore makes Incorrect Use of Privileged APIs with DocumentAuthorsEPSS 0.9%CVE-2023-26476HIGHTwo XWiki Platform UIs Expose Sensitive Information to an Unauthorized ActorEPSS 0.9%CVE-2021-43841MEDIUMXSS by SVG upload in xwiki-platformEPSS 0.9%CVE-2023-26470MEDIUMIn XWiki Platform, saving a document with a large object number leads to persistent OOM errorsEPSS 0.9%