Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2025-53837
  • github.com/xwiki/xwiki-rendering
org.xwiki.rendering:xwiki-rendering-xml has an Eval Injection issue 18 Sep
  • Fix available
  • Severity - 9.9 (Critical)
CVE-2025-66474
  • github.com/xwiki/xwiki-platform
  • github.com/xwiki/xwiki-rendering
XWiki vulnerable to remote code execution through insufficient protection against {{/html}} injection 10 Dec 2025
  • Fix available
  • Severity - 8.7 (High)
CVE-2025-53836
  • github.com/xwiki/xwiki-commons
  • github.com/xwiki/xwiki-platform
  • github.com/xwiki/xwiki-rendering
XWiki Rendering is vulnerable to RCE attacks when processing nested macros 14 Jul 2025
  • Fix available
  • Severity - 9.9 (Critical)
CVE-2025-53835
  • github.com/xwiki/xwiki-commons
  • github.com/xwiki/xwiki-platform
  • github.com/xwiki/xwiki-rendering
XWiki Rendering is vulnerable to XSS attacks through insecure XHTML syntax 14 Jul 2025
  • Fix available
  • Severity - 9.0 (Critical)
CVE-2023-37912
  • github.com/xwiki/xwiki-rendering
XWiki Rendering's footnote macro vulnerable to privilege escalation via the footnote macro 25 Oct 2023
  • Fix available
  • Severity - 9.9 (Critical)
CVE-2023-37908
  • github.com/xwiki/xwiki-rendering
org.xwiki.rendering:xwiki-rendering-xml Improper Neutralization of Invalid Characters in Identifiers in Web Pages vulnerability 25 Oct 2023
  • Fix available
  • Severity - 9.0 (Critical)
CVE-2023-32070
  • github.com/xwiki/xwiki-commons
  • github.com/xwiki/xwiki-platform
  • github.com/xwiki/xwiki-rendering
Improper Neutralization of Script in Attributes in XWiki (X)HTML renderers 10 May 2023
  • Fix available
  • Severity - 9.0 (Critical)