Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2773▼ 299 respecto a la semana anterior
Críticas / altas1298▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)207▼ 114 respecto a la semana anterior
1468 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.9% | — | Xwiki | 19/4/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on any document (e.g., their own user profile) can execute code with programming rights, leading to remote code execution. This vulnerability has been patched in XWiki 13.10.11, 14.4.8,… | |
| Modificada | Media (4.3) | 0.67% | — | Xwiki | 19/4/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. If guest has view right on any document. It's possible to create a new user using the `distribution/firstadminuser.wiki` in the wrong context. This vulnerability has been patched in XWiki 15.0-rc-1 and 14.10.1.… | |
| Modificada | Alta (8.8) | 1.1% | — | Xwiki | 19/4/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on a page (e.g., it's own user page), can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping… | |
| Modificada | Alta (8.8) | 1.9% | — | Xwiki | 19/4/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In XWiki, every user can add translations that are only applied to the current user. This also allows overriding existing translations. Such translations are often included in privileged contexts without any… | |
| Modificada | Alta (8.8) | 0.44% | — | Xwiki | 17/4/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of `org.xwiki.platform:xwiki-platform-logging-ui` it is possible to trick a user with programming rights into visiting a constructed url where e.g., by embedding an image with this URL in a… | |
| Modificada | Alta (8.8) | 1.0% | — | Xwiki | 16/4/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with the right to add an object on a page can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the styles… | |
| Modificada | Alta (8.8) | 1.0% | — | Xwiki | 16/4/2023 | 17/6/2026 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on a page (e.g., it's own user page), can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping… | |
| Modificada | Alta (8.8) | 76% | — | Xwiki | 16/4/2023 | 17/6/2026 | XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the `documentTree`… | |
| Analizada | Media (5.4) | 0.42% | — | Xwiki | 16/4/2023 | 17/6/2026 | XWiki Commons are technical libraries common to several other top level XWiki projects. A user without script rights can introduce a stored XSS by using the Live Data macro, if the last author of the content of the page has script rights. This has been patched in XWiki 14.10, 14.4.7, and 13.10.11. | |
| Modificada | Alta (7.2) | 0.90% | — | Xwiki | 16/4/2023 | 17/6/2026 | XWiki Commons are technical libraries common to several other top level XWiki projects. The Document script API returns directly a DocumentAuthors allowing to set any authors to the document, which in consequence can allow subsequent executions of scripts since this author is used for checking rights. The problem has… | |
| Modificada | Media (6.1) | 1.7% | 💥 Exploit | Xwiki | 16/4/2023 | 17/6/2026 | XWiki Commons are technical libraries common to several other top level XWiki projects. It was possible to inject some code using the URL of authenticated endpoints. This problem has been patched on XWiki 13.10.11, 14.4.7 and 14.10. | |
| Modificada | Alta (8.8) | 1.2% | — | Xwiki | 16/4/2023 | 17/6/2026 | XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the included pages in the IncludedDocuments panel.… | |
| Modificada | Alta (8.8) | 1.2% | — | Xwiki | 16/4/2023 | 17/6/2026 | XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the included pages in the included documents edit… | |
| Modificada | Alta (8.8) | 1.2% | — | Xwiki | 16/4/2023 | 17/6/2026 | XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights `WikiManager.DeleteWiki` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the `wikiId` url parameter.… | |
| Modificada | Crítica (9.8) | 2.3% | 💥 PoC | Mediawiki Score | 15/4/2023 | 17/6/2026 | The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary Scheme or shell code by using crafted… | |
| Modificada | Media (4.3) | 0.83% | — | Mediawiki | 15/4/2023 | 17/6/2026 | An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisualEditor to edit a MediaWiki user page belonging to an existing, but hidden, user, VisualEditor will disclose that the user exists. (It shouldn't because they are hidden.) This… | |
| Modificada | Alta (8.8) | 1.2% | — | Xwiki | 15/4/2023 | 17/6/2026 | XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents including the notification preferences macros can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root… | |
| Modificada | Alta (8.8) | 1.1% | — | Xwiki | 15/4/2023 | 17/6/2026 | XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents including the legacy notification activity macro can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root… | |
| Modificada | Alta (7.5) | 0.93% | — | Xwiki | 15/4/2023 | 17/6/2026 | XWiki Commons are technical libraries common to several other top level XWiki projects. Rights added to a document are not taken into account for viewing it once it's deleted. Note that this vulnerability only impact deleted documents that where containing view rights: the view rights provided on a space of a deleted… | |
| Modificada | Crítica (9) | 1.4% | — | Xwiki | 15/4/2023 | 17/6/2026 | XWiki Commons are technical libraries common to several other top level XWiki projects. The Livetable Macro wasn't properly sanitizing column names, thus allowing the insertion of raw HTML code including JavaScript. This vulnerability was also exploitable via the Documents Macro that is included since XWiki 3.5M1 and… | |
| Modificada | Media (5.4) | 0.95% | — | Xwiki | 15/4/2023 | 17/6/2026 | XWiki Commons are technical libraries common to several other top level XWiki projects. There was no check in the author of a JavaScript xobject or StyleSheet xobject added in a XWiki document, so until now it was possible for a user having only Edit Right to create such object and to craft a script allowing to… | |
| Modificada | Media (5.4) | 0.59% | — | Xwiki | 15/4/2023 | 17/6/2026 | XWiki Commons are technical libraries common to several other top level XWiki projects. The HTML macro does not systematically perform a proper neutralization of script-related html tags. As a result, any user able to use the html macro in XWiki, is able to introduce an XSS attack. This can be particularly dangerous… | |
| Modificada | Media (6.1) | 1.8% | 💥 Exploit | Xwiki | 15/4/2023 | 17/6/2026 | XWiki Commons are technical libraries common to several other top level XWiki projects. It is possible to bypass the existing security measures put in place to avoid open redirect by using a redirect such as `//mydomain.com` (i.e. omitting the `http:`). It was also possible to bypass it when using URL such as… | |
| Modificada | Media (5.3) | 0.70% | — | Xwiki | 15/4/2023 | 17/6/2026 | XWiki Commons are technical libraries common to several other top level XWiki projects. It's possible to list some users who are normally not viewable from subwiki by requesting users on a subwiki which allows only global users with `uorgsuggest.vm`. This issue only concerns hidden users from main wiki. Note that the… | |
| Modificada | Crítica (9) | 1.4% | — | Xwiki | 15/4/2023 | 17/6/2026 | XWiki Commons are technical libraries common to several other top level XWiki projects. The RSS macro that is bundled in XWiki included the content of the feed items without any cleaning in the HTML output when the parameter `content` was set to `true`. This allowed arbitrary HTML and in particular also JavaScript… |