Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2712▼ 359 respecto a la semana anterior
Críticas / altas1261▼ 231 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
1468 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 62% | — | Xwiki | 20/6/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute any wiki content with the right of the TipsPanel author by creating a tip UI extension. This has been patched in XWiki 15.1-rc-1 and 14.10.5. | |
| Modificada | Media (5.4) | 0.74% | — | Dokuwiki | 5/6/2023 | 17/6/2026 | DokuWiki antes de la fecha 04-04-2023 permite ataques de Cross-Site Scripting (XSS) a través de títulos RSS. | |
| Modificada | Media (4.3) | 0.58% | — | Mediawiki | 29/5/2023 | 17/6/2026 | An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. Upon an action=rollback operation, the alreadyrolled message can leak a user name (when the user has been revision deleted/suppressed). | |
| Modificada | Media (6.1) | 1.2% | 💥 PoC | Apache Jspwiki | 25/5/2023 | 17/6/2026 | A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.0 or later. | |
| Modificada | Crítica (9.8) | 1.1% | — | Sofawiki Project Sofawiki | 24/5/2023 | 17/6/2026 | SofaWiki <= 3.8.9 has a file upload vulnerability that leads to command execution. | |
| Modificada | Media (6.1) | 0.39% | — | Sofawiki Project Sofawiki | 18/5/2023 | 17/6/2026 | SofaWiki <=3.8.9 is vulnerable to Cross Site Scripting (XSS) via index.php. | |
| Modificada | Media (6.1) | 55% | 💥 Exploit | Xwiki | 15/5/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 14.10.4 it's possible to exploit well known parameters in XWiki URLs to perform redirection to untrusted site. This vulnerability was partially fixed in the past for XWiki 12.10.7 and 13.3RC1… | |
| Modificada | Media (6.1) | 0.65% | 💥 PoC | Xwiki RenderingXwiki | 10/5/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform. Prior to version 14.6-rc-1, HTML rendering didn't check for dangerous attributes/attribute values. This allowed cross-site scripting (XSS) attacks via attributes and link URLs, e.g., supported in XWiki syntax. This has been patched in XWiki 14.6-rc-1. There are no known… | |
| Modificada | Crítica (9) | 70% | — | Xwiki | 9/5/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform. Starting in versions 2.2-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, it's possible to execute javascript with the right of any user by leading him to a special URL on the wiki targeting a page which contains an attachment. This has been patched in XWiki… | |
| Modificada | Alta (8.8) | 0.78% | — | Xwiki | 9/5/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-2 and prior to versions 14.10.4 and 15.0-rc-1, it's possible for a user to execute anything with the right of the author of the XWiki.ClassSheet document. This has been patched in XWiki 15.0-rc-1 and 14.10.4. There are no known workarounds. | |
| Modificada | Crítica (9.6) | 0.82% | 💥 PoC | Xwiki | 9/5/2023 | 17/6/2026 | `org.xwiki.commons:xwiki-commons-xml` is an XML library used by the open-source wiki platform XWiki. The HTML sanitizer, introduced in version 14.6-rc-1, allows the injection of arbitrary HTML code and thus cross-site scripting via invalid data attributes. This vulnerability does not affect restricted cleaning in… | |
| Modificada | Crítica (9) | 1.3% | 💥 PoC | Xwiki Commons | 20/4/2023 | 17/6/2026 | XWiki Commons are technical libraries common to several other top level XWiki projects. The "restricted" mode of the HTML cleaner in XWiki, introduced in version 4.2-milestone-1 and massively improved in version 14.6-rc-1, allowed the injection of arbitrary HTML code and thus cross-site scripting via invalid HTML… | |
| Modificada | Alta (8.8) | 1.1% | — | Xwiki | 19/4/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions a user without script or programming right may edit a user profile (or any other document) with the wiki editor and add groovy script content. Viewing the document after saving it will execute… | |
| Modificada | Alta (8.8) | 1.1% | — | Xwiki | 19/4/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to display or interact with any page a user cannot access through the combination of the async and display macros. A comment with either macro will be executed when viewed… | |
| Modificada | Alta (8.8) | 78% | — | Xwiki | 19/4/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Affected versions of xwiki are subject to code injection in the `since` parameter of the `/xwiki/bin/view/XWiki/Notifications/Code/LegacyNotificationAdministration` endpoint. This provides an XWiki syntax injection… | |
| Modificada | Alta (8.8) | 76% | — | Xwiki | 19/4/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to execute anything with the right of the Scheduler Application sheet page. A user without script or programming rights, edit your user profile with the object editor and add a new object of type… | |
| Modificada | Alta (8.8) | 2.0% | — | Xwiki | 19/4/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can edit their own user profile can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki… | |
| Modificada | Alta (8.8) | 1.9% | — | Xwiki | 19/4/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read and write access to all wiki contents. The attack works… | |
| Modificada | Alta (8.8) | 1.1% | — | Xwiki | 19/4/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of `Macro.VFSTreeMacro`. This page is… | |
| Modificada | Media (6.5) | 0.53% | — | Xwiki | 19/4/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It's possible to break many translations coming from wiki pages by creating a corrupted document containing a translation object. This will lead to a broken page. The vulnerability has been patched in XWiki… | |
| Modificada | Alta (8.8) | 1.9% | — | Xwiki | 19/4/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A registered user can perform remote code execution leading to privilege escalation by injecting the proper code in the "property" field of an attachment selector, as a gadget of their own dashboard. Note that the… | |
| Modificada | Alta (8.8) | 1.1% | — | Xwiki | 19/4/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of `Invitation.InvitationCommon`. This… | |
| Modificada | Alta (7.5) | 1.0% | — | Xwiki | 19/4/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. The office document viewer macro was allowing anyone to see any file content from the hosting server, provided that the office server was connected and depending on the permissions of the user running the servlet… | |
| Modificada | Alta (8.8) | 66% | — | Xwiki | 19/4/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with view rights on `XWiki.AttachmentSelector` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping in the… | |
| Modificada | Media (5.4) | 0.57% | — | Xwiki | 19/4/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can create a space can become admin of that space through App Within Minutes. The admin right implies the script right and thus allows JavaScript injection. The vulnerability can be exploited by… |