Vulnerabilities > Xwiki > Xwiki > 11.10.8

DATE CVE VULNERABILITY TITLE RISK
2021-03-23 CVE-2021-21380 SQL Injection vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki CWE-89
6.5
2021-03-12 CVE-2021-21379 Improper Preservation of Permissions vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
xwiki CWE-281
3.5
2020-12-31 CVE-2020-13654 Improper Encoding or Escaping of Output vulnerability in Xwiki
XWiki Platform before 12.8 mishandles escaping in the property displayer.
network
low complexity
xwiki CWE-116
7.5