XWiki security policy is detailed on the following document: https://dev.xwiki.org/xwiki/bin/view/Community/SecurityPolicy/.
Security: xwiki/xwiki-platform
Security
SECURITY.md
-
Users can be created even when registration is disabled without validation via the template macroGHSA-fp36-mjw5-fmgx published
Apr 18, 2023 by tmortagneModerate -
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in xwiki-platform-web-templatesGHSA-hg5x-3w3x-7g96 published
Apr 18, 2023 by tmortagneCritical -
Privilege escalation (PR) from account/view through AdminFieldsDisplaySheet and admin.vmGHSA-rfh6-mg6h-h668 published
Apr 12, 2023 by manuelleducCritical -
RCE via unescaped translationsGHSA-4v38-964c-xjmw published
Apr 18, 2023 by tmortagneCritical -
Privilege escalation (PR) from account through FlamingoThemesCode.WebHomeSheetGHSA-vrr8-fp7c-7qgp published
Apr 12, 2023 by manuelleducCritical -
RCE in AnnotationsGHSA-h6f5-8jj5-cxhr published
Mar 1, 2023 by tmortagneCritical -
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in org.xwiki.platform:xwiki-platform-flamingo-theme-uiGHSA-f4v8-58f6-mwj4 published
Apr 12, 2023 by manuelleducCritical -
Privilege escalation via properties with wiki syntax that are executed with the wrong authorGHSA-3738-p9x3-mv9r published
Mar 1, 2023 by tmortagneCritical -
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in org.xwiki.platform:xwiki-platform-livedata-macroGHSA-hmm7-6ph9-8jf2 published
Apr 12, 2023 by tmortagneHigh -
Incorrect Use of Privileged APIs in org.xwiki.platform:xwiki-platform-oldcore with DocumentAuthorsGHSA-pwfv-3cvg-9m4c published
Apr 12, 2023 by tmortagneCritical
Learn more about advisories related to xwiki/xwiki-platform in the GitHub Advisory Database