Vulnerabilities > Xwiki > Xwiki > 12.10.7

DATE CVE VULNERABILITY TITLE RISK
2022-09-08 CVE-2022-36100 Improper Encoding or Escaping of Output vulnerability in Xwiki
XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform.
network
low complexity
xwiki CWE-116
8.8
2022-09-08 CVE-2022-36091 Missing Authorization vulnerability in Xwiki
XWiki Platform Web Templates are templates for XWiki Platform, a generic wiki platform.
network
low complexity
xwiki CWE-862
7.5
2022-05-31 CVE-2022-29258 Cross-site Scripting vulnerability in Xwiki
XWiki Platform Filter UI provides a generic user interface to convert from a XWiki Filter input stream to an output stream with settings for each stream.
network
xwiki CWE-79
4.3
2022-05-25 CVE-2022-29251 Cross-site Scripting vulnerability in Xwiki
XWiki Platform Flamingo Theme UI is a tool that allows customization and preview of any Flamingo-based skin.
network
xwiki CWE-79
4.3
2022-05-25 CVE-2022-29252 Cross-site Scripting vulnerability in Xwiki
XWiki Platform Wiki UI Main Wiki is a package for managing subwikis.
network
xwiki CWE-79
4.3
2022-05-25 CVE-2022-29253 Path Traversal vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki CWE-22
4.0
2022-05-06 CVE-2022-29161 Inadequate Encryption Strength vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki CWE-326
critical
9.8
2022-04-08 CVE-2022-24819 Privacy Violation vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki CWE-359
5.0
2022-04-08 CVE-2022-24820 Missing Authentication for Critical Function vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki CWE-306
5.3
2022-04-08 CVE-2022-24821 Incorrect Use of Privileged APIs vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki CWE-648
5.5