XWikiplatform

XWiki is a free and Open source wiki software platform written in Java with a design emphasis on extensibility. XWiki is an enterprise wiki. It includes WYSIWYG editing OpenDocument-based document import/export annotations and tagging and advanced permissions management.

Official Site:

https://xwiki.com/

Severity Summary:

Critical: 24 High: 102 Medium: 86 Low: 4
Reference
Title
Severity
XWiki Improper Neutralization of Directives in Dynamically Evaluated Code (Eval Injection) Vulnerability
High
XWiki Improper Neutralization of Directives in Dynamically Evaluated Code (Eval Injection) Vulnerability
High
XWiki Improper Control of Generation of Code (Code Injection) Vulnerability
High
XWiki Vulnerability
High
XWiki Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
XWiki Improper Encoding or Escaping of Output Vulnerability
High
XWiki Vulnerability
High
XWiki Improper Privilege Management Vulnerability
High
XWiki Improper Restriction of Excessive Authentication Attempts Vulnerability
High
XWiki Improper Restriction of XML External Entity Reference Vulnerability
High
XWiki Improper Control of Generation of Code (Code Injection) Vulnerability
High
XWikiplatform Missing Authorization Vulnerability
High
XWiki Improper Control of Generation of Code (Code Injection) Vulnerability
High
XWiki Exposure of Resource to Wrong Sphere Vulnerability
High
XWiki Improper Control of Generation of Code (Code Injection) Vulnerability
High
XWiki Improper Control of Generation of Code (Code Injection) Vulnerability
High
XWiki Improper Encoding or Escaping of Output Vulnerability
High
XWikiplatform Improper Control of Generation of Code (Code Injection) Vulnerability
High
XWikiplatform Missing Authorization Vulnerability
High
XWikiplatform Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
XWikiplatform Incorrect Authorization Vulnerability
High
XWiki Cleartext Storage of Sensitive Information Vulnerability
High
XWiki Missing Authorization Vulnerability
High
XWiki Improper Neutralization of Directives in Dynamically Evaluated Code (Eval Injection) Vulnerability
High
XWiki Improper Control of Generation of Code (Code Injection) Vulnerability
High
XWiki Improper Control of Generation of Code (Code Injection) Vulnerability
High
XWiki Server-Side Request Forgery (SSRF) Vulnerability
High
XWiki Cross-Site Request Forgery (CSRF) Vulnerability
High
XWiki Vulnerability
High
XWikiplatform Incorrect Authorization Vulnerability
High