Vulnerabilities > Xwiki > Xwiki > 1.0

DATE CVE VULNERABILITY TITLE RISK
2020-12-31 CVE-2020-13654 Improper Encoding or Escaping of Output vulnerability in Xwiki
XWiki Platform before 12.8 mishandles escaping in the property displayer.
network
low complexity
xwiki CWE-116
7.5
2010-12-30 CVE-2010-4642 Cross-Site Scripting vulnerability in Xwiki
Cross-site scripting (XSS) vulnerability in XWiki Enterprise before 2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
xwiki CWE-79
4.3
2010-12-30 CVE-2010-4641 SQL Injection vulnerability in Xwiki
SQL injection vulnerability in XWiki Enterprise before 2.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
network
low complexity
xwiki CWE-89
7.5