XWiki security policy is detailed on the following document: https://dev.xwiki.org/xwiki/bin/view/Community/SecurityPolicy/.
Security: xwiki/xwiki-platform
Security
SECURITY.md
-
Remote code execution from edit in multilingual wikis via translationsGHSA-xxp2-9c9g-7wmj published
Apr 10, 2024 by surliCritical -
Privilege escalation (PR) from user registration through PDFClassGHSA-vxwr-wpjv-qjq7 published
Apr 10, 2024 by surliCritical -
Password hash might be leaked by diff once the xobject holding them is deletedGHSA-v782-xr4w-3vqx published
Apr 10, 2024 by surliModerate -
Remote code execution from account through UIExtension parametersGHSA-c2gg-4gq4-jv5j published
Apr 10, 2024 by michituxCritical -
CSRF remote code execution through the realtime HTML Converter APIGHSA-r5vh-gc3r-r24w published
Apr 10, 2024 by surliCritical -
CSRF remote code execution through scheduler job's document referenceGHSA-37m4-hqxv-w26g published
Apr 10, 2024 by surliCritical -
CSRF in the job schedulerGHSA-j2r6-r929-v6gf published
Apr 10, 2024 by surliModerate -
Denial of Service attack through attachmentsGHSA-8959-rfxh-r4j4 published
Jan 8, 2024 by tmortagneHigh -
Remote Code Execution Vulnerability via User RegistrationGHSA-rj7p-xjv7-7229 published
Jan 8, 2024 by michituxCritical -
No right protection on rollback actionGHSA-xh35-w7wg-95v3 published
Jan 8, 2024 by surliHigh
Learn more about advisories related to xwiki/xwiki-platform in the GitHub Advisory Database