Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| xwiki | xwiki-platform | >= 10.11.1, < 13.10.11 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-29514 | 10.0 CRITICAL | Code injection in template provider administration in xwiki-platform |
| CVE-2023-29510 | 10.0 CRITICAL | Code injection via unescaped translations in xwiki-platform |
| CVE-2023-29523 | 10.0 CRITICAL | Code injection in display method used in user profiles in xwiki-platform |
| CVE-2023-29524 | 10.0 CRITICAL | Code injection from account through XWiki.SchedulerJobSheet in xwiki-platform |
| CVE-2023-29525 | 10.0 CRITICAL | Privilege escalation from view right on XWiki.Notifications.Code.LegacyNotificationAdminis |
| CVE-2023-29527 | 10.0 CRITICAL | Code injection from account through AWM view sheet in xwiki platform |
| CVE-2023-29516 | 9.9 CRITICAL | Code injection from view right on XWiki.AttachmentSelector in xwiki-platform |
| CVE-2023-29512 | 9.9 CRITICAL | Code injection in xwiki-platform-web-templates |
| CVE-2023-29522 | 9.9 CRITICAL | Code injection from view right on XWiki.ClassSheet in xwiki-platform |
| CVE-2023-29518 | 9.9 CRITICAL | Code injection from view right using Invitation.InvitationCommon in xwiki-platform |
| CVE-2023-29519 | 9.1 CRITICAL | Code injection in org.xwiki.platform:xwiki-platform-attachment-ui |
| CVE-2023-29521 | 8.4 HIGH | Code injection from account/view through VFS Tree macro in xwiki-platform |
| CVE-2023-29515 | 7.7 HIGH | Cross-site scripting (XSS) in xwiki-platform |
| CVE-2023-29517 | 7.5 HIGH | Exposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-pla |
| CVE-2023-29513 | 5.0 MEDIUM | Users can be created even when registration is disabled without validation via the templat |
| CVE-2023-29520 | 4.3 MEDIUM | Page render failure due to broken translations in xwiki-platform |
Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.