An open API service providing security vulnerability metadata for many open source software ecosystems.

maven

org.xwiki.platform:xwiki-platform-oldcore

maven

Security Advisories for org.xwiki.platform:xwiki-platform-oldcore in maven

High
about 2 months ago

XWiki exposes passwords and emails stored in fields not named password/email in xml.vm GSA_kwCzR0hTQS01N3EyLTZjcDQtOW1xM84ABKyD

maven org.xwiki.platform:xwiki-platform-legacy-oldcore, org.xwiki.platform:xwiki-platform-oldcore
High
about 2 months ago

XWiki leaks password hashes and other accessible password properties GSA_kwCzR0hTQS1yMzhtLWNncGctcWo2Oc4ABKyC

maven org.xwiki.platform:xwiki-platform-legacy-oldcore, org.xwiki.platform:xwiki-platform-oldcore
Critical
about 1 year ago

XWiki Platform allows XSS through XClass name in string properties GSA_kwCzR0hTQS13Y2c5LXBncXYteG01ds4AA-yA

maven org.xwiki.platform:xwiki-platform-oldcore
Critical
over 1 year ago

XWiki Platform allows remote code execution from user account GSA_kwCzR0hTQS1qNTg0LWoydmotM2Y5M84AA9Pv

maven org.xwiki.platform:xwiki-platform-oldcore
High
over 1 year ago

XWiki has no right protection on rollback action GSA_kwCzR0hTQS14aDM1LXc3d2ctOTV2M84AA4Qi

maven org.xwiki.platform:xwiki-platform, org.xwiki.platform:xwiki-platform-oldcore
Critical
over 2 years ago

Upgrading doesn't prevent exploiting vulnerable XWiki documents GSA_kwCzR0hTQS04cTlxLXI5djItNjQ0bc4AA0KR

maven org.xwiki.platform:xwiki-platform-oldcore
Critical
over 2 years ago

XWiki Platform's async and display macro allow displaying and interacting with any document in restricted mode GSA_kwCzR0hTQS1ncHE1LTdwMzQtdnF4Nc4AAy58

maven org.xwiki.platform:xwiki-platform-rendering-async-macro, org.xwiki.platform:xwiki-platform-oldcore
Moderate
over 2 years ago

XWiki Platform subject to Uncontrolled Resource Consumption GSA_kwCzR0hTQS05MndwLXI3aG0tNDJnN84AAx7S

maven org.xwiki.platform:xwiki-platform-oldcore
Critical
over 2 years ago

XWiki Platform vulnerable to privilege escalation via properties with wiki syntax that are executed with wrong author GSA_kwCzR0hTQS0zNzM4LXA5eDMtbXY5cs4AAx7O

maven org.xwiki.platform:xwiki-platform-legacy-oldcore, org.xwiki.platform:xwiki-platform-oldcore
High
almost 3 years ago

Creation of new database tables through login form on PostgreSQL GSA_kwCzR0hTQS00eDVyLTZ2MjYtN2o0ds4AAv_S

maven org.xwiki.platform:xwiki-platform-oldcore
High
about 3 years ago

XWiki Platform Improper Authorization check for inactive users GSA_kwCzR0hTQS1qZ2M4LWd2Y3gtOXZmeM4AAu1i

maven org.xwiki.platform:xwiki-platform-oldcore
Low
over 3 years ago

Path Traversal in XWiki Platform GSA_kwCzR0hTQS05cXJwLWg3ZnctNDJoZ84AArTY

maven org.xwiki.platform:xwiki-platform-oldcore
Moderate
over 3 years ago

XWiki Remote Code Execution GSA_kwCzR0hTQS1oNWptLWpqZ3gtcTJ3Zs2VbA

maven org.xwiki.platform:xwiki-platform-oldcore
Moderate
over 3 years ago

Cross-site Scripting by SVG upload in xwiki-platform GSA_kwCzR0hTQS05anE5LWMyY3YtcGNyas0pfw

maven org.xwiki.platform:xwiki-platform-tool-configuration-resources, org.xwiki.platform:xwiki-platform-oldcore
Moderate
over 3 years ago

Missing authorization in xwiki-platform GSA_kwCzR0hTQS0yamhtLXFwNDgtaHY1as0p2A

maven org.xwiki.platform:xwiki-platform-oldcore
Moderate
over 3 years ago

URL Redirection to Untrusted Site ('Open Redirect') GSA_kwCzR0hTQS1qcDU1LXZ2bWYtNjNtds0p1Q

maven org.xwiki.platform:xwiki-platform-oldcore
Moderate
over 3 years ago

Missing authorization in xwiki-platform GSA_kwCzR0hTQS1nZjd4LTJqMngtN2Y3M80p1A

maven org.xwiki.platform:xwiki-platform-oldcore
Moderate
over 3 years ago

Partial authorization bypass on document save in xwiki-platform GSA_kwCzR0hTQS1mNGNqLTNxM2gtODg0cs0p0g

maven org.xwiki.platform:xwiki-platform-oldcore
Critical
over 4 years ago

XSS Cross Site Scripting MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTVjNjYtdjI5aC14amg4

maven org.xwiki.platform:xwiki-platform-web, org.xwiki.platform:xwiki-platform-oldcore
High
almost 5 years ago

RCE in XWiki MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTVodjYtbWg4cS1xOXY4

maven org.xwiki.platform:xwiki-platform-oldcore