Vulnerabilities > Xwiki > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-11-23 CVE-2022-41932 Allocation of Resources Without Limits or Throttling vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki CWE-770
5.3
2022-11-23 CVE-2022-41933 Insufficiently Protected Credentials vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki CWE-522
6.5
2022-11-23 CVE-2022-41935 Unspecified vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki
4.3
2022-11-23 CVE-2022-41929 Unspecified vulnerability in Xwiki
org.xwiki.platform:xwiki-platform-oldcore is missing authorization in User#setDisabledStatus, which may allow an incorrectly authorized user with only Script rights to enable or disable a user.
network
low complexity
xwiki
4.9
2022-09-08 CVE-2022-36095 Unspecified vulnerability in Xwiki
XWiki Platform is a generic wiki platform.
network
low complexity
xwiki
4.3
2022-09-08 CVE-2022-36097 Cross-site Scripting vulnerability in Xwiki
XWiki Platform Attachment UI provides a macro to easily upload and select attachments for XWiki Platform, a generic wiki platform.
network
low complexity
xwiki CWE-79
6.1
2022-09-07 CVE-2022-31167 Missing Authorization vulnerability in Xwiki
XWiki Platform Security Parent POM contains the security APIs for XWiki Platform, a generic wiki platform.
network
low complexity
xwiki CWE-862
6.5
2022-05-31 CVE-2022-29258 Cross-site Scripting vulnerability in Xwiki
XWiki Platform Filter UI provides a generic user interface to convert from a XWiki Filter input stream to an output stream with settings for each stream.
network
low complexity
xwiki CWE-79
6.1
2022-05-25 CVE-2022-29251 Cross-site Scripting vulnerability in Xwiki
XWiki Platform Flamingo Theme UI is a tool that allows customization and preview of any Flamingo-based skin.
network
low complexity
xwiki CWE-79
6.1
2022-05-25 CVE-2022-29252 Cross-site Scripting vulnerability in Xwiki
XWiki Platform Wiki UI Main Wiki is a package for managing subwikis.
network
low complexity
xwiki CWE-79
6.1