XWiki security policy is detailed on the following document: https://dev.xwiki.org/xwiki/bin/view/Community/SecurityPolicy/.
Security: xwiki/xwiki-platform
Security
SECURITY.md
-
Exposed Dangerous Method or Function in org.xwiki.platform:xwiki-platform-store-filesystem-oldcoreGHSA-8692-g6g9-gm5p published
Mar 1, 2023 by manuelleducModerate -
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in org.xwiki.platform:xwiki-platform-flamingo-theme-uiGHSA-x2qm-r4wx-8gpg published
Mar 1, 2023 by manuelleducCritical -
Macro execution as any user without programming rights through the context macroGHSA-859x-p6jp-rc2w published
Mar 1, 2023 by tmortagneModerate -
Multiple instances of stored cross-site scripting (XSS) via HTML and raw macroGHSA-vxf7-mx22-jr24 published
Apr 12, 2023 by tmortagneCritical -
URL Redirection to Untrusted Site ('Open Redirect') in org.xwiki.platform:xwiki-platform-oldcoreGHSA-xwph-x6xj-wggv published
Apr 12, 2023 by tmortagneModerate -
Unauthenticated user can have information about hidden users on subwikis through uorgsuggest.vmGHSA-vvp7-r422-rx83 published
Apr 12, 2023 by tmortagneLow -
Exposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-livetable-ui,org.xwiki.platform:xwiki-platform-wiki-ui-mainwikiGHSA-5cf8-vrr8-8hjm published
Mar 1, 2023 by manuelleducHigh -
Exposure of Private Personal Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-rest-serverGHSA-p88w-fhxw-xvcc published
Nov 21, 2022 by surliModerate -
Exposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-livetable-uiGHSA-p2x4-6ghr-6vmq published
Nov 21, 2022 by surliModerate -
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in org.xwiki.platform:xwiki-platform-rendering-macro-rssGHSA-c885-89fw-55qr published
Apr 12, 2023 by tmortagneCritical
Learn more about advisories related to xwiki/xwiki-platform in the GitHub Advisory Database