Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| xwiki | xwiki-platform | >= 15.9-rc-1, < 15.10.16 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-49586 | XWiki allows remote code execution through preview of XClass changes in AWM editor | |
| CVE-2025-49585 | XWiki does not require right warnings for XClass definitions | |
| CVE-2025-49584 | XWiki makes title of inaccessible pages available through the class property values REST A | |
| CVE-2025-49583 | XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRenderer | |
| CVE-2025-49582 | XWiki's required right warnings for macros are incomplete | |
| CVE-2025-49581 | XWiki allows remote code execution through default value of wiki macro wiki-type parameter | |
| CVE-2025-49580 | XWiki allows privilege escalation through link refactoring |
No comments yet