xwiki
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 299 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 31, 2005 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →XWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName}
XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slash
Server-Side Request Forgery (SSRF) in PlantUML Macro via 'server' parameter
CryptPad unbounded WebSocket frame flood
XWiki's REST APIs can list all pages/spaces, leading to unavailability
XWiki has Reflected Cross-Site Scripting (XSS) in its page history compare functionality
XWiki Platform affected by remote code execution with script right through unprotected Velocity scripting API
XWiki Blog Application home page vulnerable to Stored XSS via Post Title
XWiki Platform affected by click-jacking through CSS injection in comments
XWiki Affected by Reflected Cross-Site Scripting (XSS) in Error Messages
Monitor xwiki in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.