An open API service providing security vulnerability metadata for many open source software ecosystems.

Browse Security Advisories

High Security Advisories for https://github.com/xwiki/xwiki-platform Clear Filters

High
4 months ago

XWiki exposes passwords and emails stored in fields not named password/email in xml.vm GSA_kwCzR0hTQS01N3EyLTZjcDQtOW1xM84ABKyD

maven org.xwiki.platform:xwiki-platform-legacy-oldcore, org.xwiki.platform:xwiki-platform-oldcore
High
4 months ago

XWiki leaks password hashes and other accessible password properties GSA_kwCzR0hTQS1yMzhtLWNncGctcWo2Oc4ABKyC

maven org.xwiki.platform:xwiki-platform-legacy-oldcore, org.xwiki.platform:xwiki-platform-oldcore
High
5 months ago

XWiki does not require right warnings for XClass definitions GSA_kwCzR0hTQS01OXc2LXI5aG0tNDM5aM4ABJCT

maven org.xwiki.platform:xwiki-platform-security-requiredrights-default
High
5 months ago

XWiki's required right warnings for macros are incomplete GSA_kwCzR0hTQS1jMzJtLTI3cGotNHhjas4ABJCN

maven org.xwiki.platform:xwiki-platform-rendering-macro-context, org.xwiki.platform:xwiki-platform-security-requiredrights-default, org.xwiki.platform:xwiki-platform-rendering-macro-cache, org.xwiki.platform:xwiki-platform-rendering-xwiki
High
5 months ago

XWiki allows privilege escalation through link refactoring GSA_kwCzR0hTQS1qbTQzLWhycTctcjd3Ns4ABJCM

maven org.xwiki.platform:xwiki-platform-refactoring-default
High
7 months ago

Any user with view access to the XWiki space can change the authenticator GSA_kwCzR0hTQS1mOWM2LTJmOXAtODJqas4ABHSi

maven org.xwiki.platform:xwiki-platform-security-authentication-ui
High
8 months ago

The WikiManager REST API allows any user to create wikis GSA_kwCzR0hTQS1nZnAyLTZxaG0tN3g0M84ABFp4

maven org.xwiki.platform:xwiki-platform-wiki-rest-default
High
8 months ago

XWiki uses the wrong wiki reference in AuthorizationManager GSA_kwCzR0hTQS1ncTMyLTc1OGMtM3dtM84ABFp2

maven org.xwiki.platform:xwiki-platform-security-authorization-api
High
almost 2 years ago

XWiki vulnerable to Denial of Service attack through attachments GSA_kwCzR0hTQS04OTU5LXJmeGgtcjRqNM4AA4Qk

maven org.xwiki.platform:xwiki-platform-distribution-war
High
almost 2 years ago

XWiki has no right protection on rollback action GSA_kwCzR0hTQS14aDM1LXc3d2ctOTV2M84AA4Qi

maven org.xwiki.platform:xwiki-platform, org.xwiki.platform:xwiki-platform-oldcore
High
almost 2 years ago

Velocity execution without script right through tree macro GSA_kwCzR0hTQS1wNWY4LXFmMjQtMjRjas4AA36y

maven org.xwiki.platform:xwiki-platform-index-tree-macro
High
almost 2 years ago

Solr search discloses password hashes of all users GSA_kwCzR0hTQS1wNmNwLTZyMzUtMzJtaM4AA324

maven org.xwiki.platform:xwiki-platform-search-solr-api
High
about 2 years ago

Privilege escalation (PR)/remote code execution from account through Menu.UIExtensionSheet GSA_kwCzR0hTQS12MnJyLXh3OTUtd2NqeM4AA2sE

maven org.xwiki.platform:xwiki-platform-menu-ui, org.xwiki.platform:xwiki-platform-menu
High
over 2 years ago

XWiki Platform may show email addresses in clear in REST results GSA_kwCzR0hTQS04ZzljLWM5Y20tOWM1Ns4AAz9q

maven org.xwiki.platform:xwiki-platform-rest-server
High
over 2 years ago

XWiki Platform may retrieve email addresses of all users GSA_kwCzR0hTQS03dnI3LWNnaGgtY2g2M84AAz9o

maven org.xwiki.platform:xwiki-platform-livetable-ui
High
over 2 years ago

Improper Neutralization of Script-Related HTML Tags (XSS) in the LiveTable Macro GSA_kwCzR0hTQS02dmdoLTlyM2MtMmN4cM4AAyu8

maven org.xwiki.platform:xwiki-web-standard, org.xwiki.platform:xwiki-platform-web, org.xwiki.platform:xwiki-platform-web-templates, org.xwiki.platform:xwiki-platform-flamingo, org.xwiki.platform:xwiki-platform-flamingo-skin, org.xwiki.platform:xwiki-platform-flamingo-skin-resources
High
over 2 years ago

XWiki Platform packages Expose Sensitive Information to an Unauthorized Actor GSA_kwCzR0hTQS01Y2Y4LXZycjgtOGhqbc4AAx7N

maven org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki, org.xwiki.platform:xwiki-platform-livetable-ui
High
almost 3 years ago

Creation of new database tables through login form on PostgreSQL GSA_kwCzR0hTQS00eDVyLTZ2MjYtN2o0ds4AAv_S

maven org.xwiki.platform:xwiki-platform-oldcore
High
about 3 years ago

XWiki Platform Improper Authorization check for inactive users GSA_kwCzR0hTQS1qZ2M4LWd2Y3gtOXZmeM4AAu1i

maven org.xwiki.platform:xwiki-platform-oldcore
High
about 3 years ago

XWiki Platform Web Templates vulnerable to Missing Authorization, Exposure of Private Personal Information to Unauthorized Actor GSA_kwCzR0hTQS01OTl2LXc0OGgtcmpybc4AAu1h

maven org.xwiki.platform:xwiki-platform-web, org.xwiki.platform:xwiki-platform-web-templates
High
about 3 years ago

XWiki Platform Web Templates vulnerable to Unauthorized User Registration Through the Distribution Wizard GSA_kwCzR0hTQS1oNWozLTV4NjMtcDhqds4AAu1K

maven org.xwiki.platform:xwiki-platform-web, org.xwiki.platform:xwiki-platform-web-templates
High
over 3 years ago

Cross-site Scripting in wiki manager join wiki page GSA_kwCzR0hTQS1waDV4LWgyM3gtN3E1cc4AArNJ

maven org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki
High
over 3 years ago

Cross-site Scripting in the Flamingo theme manager GSA_kwCzR0hTQS12bWhoLXhoM2ctajk5Ms4AArNI

maven org.xwiki.platform:xwiki-platform-flamingo-theme-ui
High
almost 4 years ago

Cross-Site Request Forgery in xwiki-platform GSA_kwCzR0hTQS12aDVjLWpxZmctbWhyaM0pfg

maven org.xwiki.platform:xwiki-platform-administration-ui
High
almost 4 years ago

Cross site scripting in registration template in xwiki-platform GSA_kwCzR0hTQS1neDZoLTkzNmMtdnJycs0p3Q

maven org.xwiki.platform:xwiki-platform-web-templates
High
almost 4 years ago

Improper escaping in XWiki Platform MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXA5M2MtaDhxbS03MjU2

maven org.xwiki.platform:xwiki-platform-web
High
almost 4 years ago

Remote code execution in xwiki-platform GSA_kwCzR0hTQS1tZ2p3LTJ3cnAtcjUzNc0p0w

maven org.xwiki.platform:xwiki-platform-administration-ui
High
over 4 years ago

Rating Script Service expose XWiki to SQL injection MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTc5cmctN212My1qcnI1

maven org.xwiki.platform:xwiki-platform-ratings-api
High
about 5 years ago

RCE in XWiki MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTVodjYtbWg4cS1xOXY4

maven org.xwiki.platform:xwiki-platform-oldcore

Filter by Severity

Filter by Ecosystem

Filter by Package

Microsoft.ChakraCore 234 tensorflow 122 tensorflow-cpu 114 tensorflow-gpu 114 magento/community-edition 104 moodle/moodle 62 org.jenkins-ci.main:jenkins-core 56 com.fasterxml.jackson.core:jackson-databind 43 magento/project-community-edition 40 Django 38 dolibarr/dolibarr 35 drupal/core 32 librenms/librenms 32 mlflow 32 org.apache.tomcat:tomcat 32 typo3/cms 32 github.com/rancher/rancher 31 pimcore/pimcore 30 salt 29 apache-airflow 29 Plone 28 phpmyadmin/phpmyadmin 28 microweber/microweber 27 typo3/cms-core 26 nokogiri 26 com.liferay.portal:release.portal.bom 25 drupal/drupal 24 ansible 24 opencv-contrib-python 23 opencv-python 23 org.apache.struts:struts2-core 22 thorsten/phpmyfaq 22 com.thoughtworks.xstream:xstream 22 com.jfinal:jfinal 21 django 21 symfony/symfony 21 github.com/hashicorp/vault 20 matrix-synapse 19 com.liferay.portal:release.dxp.bom 19 org.jenkins-ci.plugins:script-security 19 pocketmine/pocketmine-mp 18 org.apache.tomcat.embed:tomcat-embed-core 18 pillow 18 Pillow 18 rdiffweb 17 gradio 17 parse-server 17 io.undertow:undertow-core 17 open-webui 17 github.com/grafana/grafana 17 openssl-src 16 keystone 16 Microsoft.AspNetCore.App.Runtime.win-x86 16 Microsoft.AspNetCore.App.Runtime.win-x64 16 getgrav/grav 16 github.com/zitadel/zitadel 15 nilsteampassnet/teampass 15 github.com/usememos/memos 15 github.com/hashicorp/consul 15 org.xwiki.platform:xwiki-platform-oldcore 15 org.keycloak:keycloak-core 14 vyper 14 Microsoft.AspNetCore.App.Runtime.win-arm 14 Microsoft.NetCore.App.Runtime.win-arm 14 net.mingsoft:ms-mcms 14 centreon/centreon 14 flowise 14 shopware/platform 14 craftcms/cms 14 golang.org/x/net 13 Microsoft.NetCore.App.Runtime.win-x64 13 Microsoft.AspNetCore.App.Runtime.win-arm64 13 org.keycloak:keycloak-services 13 shopware/core 13 apache-superset 13 Microsoft.NetCore.App.Runtime.win-arm64 13 org.apache.solr:solr-core 13 Microsoft.AspNetCore.App.Runtime.osx-x64 13 mindsdb 13 rubygems-update 13 Microsoft.NetCore.App.Runtime.win-x86 13 Microsoft.AspNetCore.App.Runtime.linux-x64 13 rack 13 baserproject/basercms 12 Microsoft.AspNetCore.App.Runtime.linux-arm64 12 silverstripe/framework 12 org.apache.openmeetings:openmeetings-parent 12 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 12 phpoffice/phpspreadsheet 12 electron 12 mautic/core 12 Microsoft.AspNetCore.App.Runtime.linux-arm 12 activerecord 12 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 12 froxlor/froxlor 11 github.com/hashicorp/nomad 11 github.com/argoproj/argo-cd 11 actionpack 11 gogs.io/gogs 11 org.springframework.security:spring-security-core 11 cockpit-hq/cockpit 11 deno 11 next 11 directus 11 intelliants/subrion 11 org.keycloak:keycloak-parent 11 github.com/argoproj/argo-cd/v2 11 laravel/framework 10 openmage/magento-lts 10 github.com/traefik/traefik/v2 10 funadmin/funadmin 10 nova 10 snipe/snipe-it 10 github.com/ollama/ollama 10 k8s.io/kubernetes 10 surrealdb 10 github.com/mattermost/mattermost/server/v8 10 github.com/nats-io/nats-server/v2 10 org.apache.tomcat:tomcat-catalina 10 Microsoft.NetCore.App.Runtime.osx-x64 9 Microsoft.NetCore.App.Runtime.osx-arm64 9 Microsoft.NetCore.App.Runtime.linux-x64 9 ckb 9 rusqlite 9 org.cloudfoundry.identity:cloudfoundry-identity-server 9 litellm 9 pyload-ng 9 Microsoft.NetCore.App.Runtime.linux-musl-arm 9 neutron 9 Microsoft.NetCore.App.Runtime.linux-musl-x64 9 aim 9 h2o 9 Microsoft.NetCore.App.Runtime.linux-arm 9 apollo-router 9 org.apache.geode:geode-core 9 lollms 9 org.bouncycastle:bcprov-jdk14 9 org.apache.hadoop:hadoop-main 9 mercurial 9 @anthropic-ai/claude-code 9 github.com/ethereum/go-ethereum 9 cobbler 9 Microsoft.NetCore.App.Runtime.linux-musl-arm64 9 org.apache.nifi:nifi 9 zendframework/zendframework1 9 Microsoft.NetCore.App.Runtime.linux-arm64 9 org.elasticsearch:elasticsearch 8 composer/composer 8 org.bouncycastle:bcprov-jdk15 8 org.eclipse.jetty:jetty-server 8 cryptography 8 org.craftercms:crafter-studio 8 phpbb/phpbb 8 org.springframework:spring-core 8 github.com/docker/docker 8 smarty/smarty 8 yeswiki/yeswiki 8 vllm 8 plone 8 october/system 8 mantisbt/mantisbt 8 github.com/mattermost/mattermost-server 8 github.com/sylabs/singularity 8 Microsoft.AspNetCore.App.Runtime.linux-musl-arm 8 github.com/opencontainers/runc 8 moin 8 ai.h2o:h2o-core 8 github.com/filebrowser/filebrowser/v2 7 Microsoft.NETCore.App.Runtime.win-x86 7 org.apache.kylin:kylin 7 DotNetNuke.Core 7 k8s.io/ingress-nginx 7 tar 7 org.apache.struts.xwork:xwork-core 7 ryu 7 magento/core 7 com.xuxueli:xxl-job 7 org.apache.dolphinscheduler:dolphinscheduler 7 org.jenkins-ci.plugins.workflow:workflow-cps 7 org.apache.tomcat:tomcat-coyote 7 Microsoft.NETCore.App.Runtime.win-x64 7 @strapi/strapi 7 OPCFoundation.NetStandard.Opc.Ua.Core 7 Microsoft.NETCore.App.Runtime.win-arm64 7 strapi 7 cakephp/cakephp 7 contao/core-bundle 7 org.apache.inlong:manager-pojo 7 Microsoft.AspNetCore.App.Runtime.osx-arm64 7 github.com/zitadel/zitadel/v2 7 org.jenkins-ci.plugins.workflow:workflow-cps-global-lib 7 phpmailer/phpmailer 7 pgadmin4 7 codeigniter4/framework 7 opencv-python-headless 7 golang.org/x/crypto 7 cn.hutool:hutool-core 7 sentry 6 mobsf 6 Magick.NET-Q16-AnyCPU 6

Filter by Repository

https://github.com/chakra-core/ChakraCore 204 https://github.com/tensorflow/tensorflow 122 https://github.com/xwiki/xwiki-platform 64 https://github.com/django/django 52 https://github.com/FasterXML/jackson-databind 44 https://github.com/jenkinsci/jenkins 43 https://github.com/apache/tomcat 40 https://github.com/apache/airflow 39 https://github.com/python-pillow/Pillow 35 https://github.com/moodle/moodle 34 https://github.com/keycloak/keycloak 32 https://github.com/pimcore/pimcore 28 https://github.com/librenms/librenms 28 https://github.com/dotnet/runtime 28 https://github.com/rancher/rancher 27 https://github.com/opencv/opencv 25 https://github.com/microweber/microweber 25 https://github.com/symfony/symfony 23 https://github.com/x-stream/xstream 22 https://github.com/sparklemotion/nokogiri 21 https://github.com/Dolibarr/dolibarr 21 https://github.com/apache/struts 20 https://github.com/spring-projects/spring-framework 19 https://github.com/ansible/ansible 19 https://github.com/thorsten/phpmyfaq 18 https://github.com/pmmp/PocketMine-MP 18 https://github.com/TYPO3/typo3 18 https://github.com/zitadel/zitadel 18 https://github.com/ikus060/rdiffweb 17 https://github.com/gradio-app/gradio 17 https://github.com/parse-community/parse-server 17 https://github.com/mlflow/mlflow 16 https://github.com/plone/Products.CMFPlone 16 https://github.com/github/advisory-database 15 https://github.com/kubernetes/kubernetes 15 https://github.com/apache/inlong 15 https://github.com/rails/rails 15 https://github.com/getgrav/grav 14 https://github.com/openstack/keystone 14 https://github.com/vyperlang/vyper 14 https://github.com/grafana/grafana 14 https://github.com/usememos/memos 14 https://github.com/jenkinsci/script-security-plugin 14 https://github.com/argoproj/argo-cd 14 https://github.com/undertow-io/undertow 13 https://github.com/saltstack/salt 13 https://github.com/matrix-org/synapse 13 https://github.com/mindsdb/mindsdb 13 https://github.com/liferay/liferay-portal 13 https://github.com/mautic/mautic 13 https://github.com/hashicorp/consul 12 https://github.com/electron/electron 12 https://github.com/directus/directus 12 https://github.com/PHPOffice/PhpSpreadsheet 12 https://github.com/run-llama/llama_index 11 https://github.com/strapi/strapi 11 https://github.com/hashicorp/vault 11 https://github.com/silverstripe/silverstripe-framework 11 https://github.com/apache/nifi 11 https://github.com/denoland/deno 11 https://github.com/centreon/centreon 10 https://github.com/funadmin/funadmin 10 https://github.com/golang/go 10 https://github.com/rack/rack 10 https://github.com/go-gitea/gitea 10 https://github.com/netty/netty 10 https://github.com/surrealdb/surrealdb 10 https://github.com/FlowiseAI/Flowise 10 https://github.com/dotnet/aspnetcore 10 https://github.com/OpenMage/magento-lts 10 https://github.com/octobercms/october 10 https://github.com/h2oai/h2o-3 9 https://github.com/laravel/framework 9 https://github.com/cui2shark/cms 9 https://github.com/nervosnetwork/ckb 9 https://github.com/nilsteampassnet/teampass 9 https://github.com/rusqlite/rusqlite 9 https://github.com/apache/cxf 9 https://github.com/traefik/traefik 9 https://github.com/opencontainers/runc 9 https://github.com/apache/camel 9 https://github.com/vercel/next.js 9 https://github.com/geoserver/geoserver 9 https://github.com/cloudfoundry/uaa 9 https://github.com/snipe/snipe-it 9 https://github.com/anthropics/claude-code 9 https://github.com/openstack/nova 9 https://github.com/spring-projects/spring-security 9 https://github.com/pyload/pyload 9 https://github.com/OpenRefine/OpenRefine 8 https://github.com/OPCFoundation/UA-.NETStandard 8 https://github.com/bcgit/bc-java 8 https://github.com/pyca/cryptography 8 https://github.com/dnnsoftware/Dnn.Platform 8 https://github.com/vllm-project/vllm 8 https://github.com/apollographql/router 8 https://github.com/backstage/backstage 8 https://github.com/shopware/platform 8 https://github.com/PaddlePaddle/Paddle 8 https://github.com/gogs/gogs 8 https://github.com/phpmyadmin/phpmyadmin 8 https://github.com/craftcms/cms 8 https://github.com/apache/kylin 8 https://github.com/TYPO3/TYPO3.CMS 8 https://github.com/open-webui/open-webui 8 https://github.com/nats-io/nats-server 8 https://github.com/cockpit-hq/cockpit 8 https://github.com/contao/contao 7 https://github.com/YesWiki/yeswiki 7 https://github.com/parisneo/lollms 7 https://github.com/apache/activemq 7 https://github.com/xuxueli/xxl-job 7 https://github.com/eclipse/jetty.project 7 https://github.com/magento/magento2 7 https://github.com/mattermost/mattermost 7 https://github.com/DSpace/DSpace 7 https://github.com/filebrowser/filebrowser 7 https://github.com/faucetsdn/ryu 7 https://github.com/composer/composer 7 https://github.com/mantisbt/mantisbt 7 https://github.com/rubygems/rubygems 7 https://github.com/PHPMailer/PHPMailer 7 https://github.com/MobSF/Mobile-Security-Framework-MobSF 7 https://github.com/smarty-php/smarty 7 https://github.com/cobbler/cobbler 7 https://github.com/nilsteampassnet/TeamPass 6 https://github.com/cefsharp/CefSharp 6 https://github.com/ethyca/fides 6 https://github.com/kyverno/kyverno 6 https://github.com/TYPO3-CMS/core 6 https://github.com/langchain-ai/langchain 6 https://github.com/ImageMagick/ImageMagick 6 https://github.com/OpenNMS/opennms 6 https://github.com/gravitl/netmaker 6 https://github.com/shopware/shopware 6 https://github.com/quarkusio/quarkus 6 https://github.com/guzzle/guzzle 6 https://github.com/minio/minio 6 https://github.com/aubio/aubio 6 https://github.com/sequelize/sequelize 6 https://github.com/RaspAP/raspap-webgui 6 https://github.com/OpenZeppelin/openzeppelin-contracts 6 https://github.com/froxlor/froxlor 6 https://github.com/haxtheweb/issues 6 https://github.com/cilium/cilium 6 https://github.com/goharbor/harbor 6 https://github.com/npm/node-tar 6 https://github.com/protocolbuffers/protobuf 6 https://github.com/cosmos/cosmos-sdk 6 https://github.com/intelliants/subrion 6 https://github.com/hyperledger/fabric 6 https://github.com/CVEProject/cvelist 6 https://github.com/DrunkenShells/Disclosures 6 https://github.com/kiwitcms/Kiwi 6 https://github.com/getkirby/kirby 6 https://github.com/nautobot/nautobot 6 https://github.com/getsentry/sentry 6 https://github.com/dromara/hutool 6 https://github.com/WWBN/AVideo 6 https://github.com/phpseclib/phpseclib 6 https://github.com/drupal/core 6 https://github.com/pgadmin-org/pgadmin4 6 https://github.com/opencast/opencast 6 https://github.com/matrix-org/matrix-js-sdk 6 https://github.com/containers/podman 6 https://github.com/ls1intum/Ares 6 https://github.com/Graylog2/graylog2-server 6 https://github.com/istio/istio 6 https://github.com/bodil/sized-chunks 6 https://github.com/pear/Archive_Tar 5 https://github.com/cakephp/cakephp 5 https://github.com/forkcms/forkcms 5 https://github.com/bolt/bolt 5 https://github.com/keras-team/keras 5 https://github.com/ethereum/go-ethereum 5 https://github.com/cri-o/cri-o 5 https://github.com/element-hq/synapse 5 https://github.com/faisalman/ua-parser-js 5 https://github.com/apache/hadoop 5 https://github.com/sebhildebrandt/systeminformation 5 https://github.com/docker/docker 5 https://github.com/beego/beego 5 https://github.com/openstack/neutron 5 https://github.com/HumanSignal/label-studio 5 https://github.com/apache/dolphinscheduler 5 https://github.com/cloudflare/cfrpki 5 https://github.com/zopefoundation/Zope 5 https://github.com/BlackFan/client-side-prototype-pollution 5 https://github.com/statamic/cms 5 https://github.com/n8n-io/n8n 5 https://github.com/hashicorp/go-getter 5 https://github.com/answerdev/answer 5 https://github.com/PrestaShop/PrestaShop 5 https://github.com/opencart/opencart 5 https://github.com/apache/geode 5 https://github.com/thorsten/phpMyFAQ 5 https://github.com/codeigniter4/CodeIgniter4 5 https://github.com/IBAX-io/go-ibax 5 https://sourceforge.net/projects/phpmyadmin.sourceforge.net 5