Xwiki-platform
This hub aggregates every CVE we track for Xwiki-platform, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
228
CVEs tracked
111
Critical
57
High
1
In CISA KEV
Severity distribution
CRITICAL111HIGH57MEDIUM54LOW6
Monthly trend
4
2
3
0
0
5
1
1
3
10
1
9
2
4
2
1
0
3
1
1
0
2
1
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Xwiki-platform.
- CVE-2026-33137XWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName}7.5
- CVE-2026-40105XWiki has Reflected Cross-Site Scripting (XSS) in its page history compare functionality6.1
- CVE-2026-33229XWiki Platform affected by remote code execution with script right through unprotected Velocity scripting API9.8
- CVE-2026-26000XWiki Platform affected by click-jacking through CSS injection in comments6.1
- CVE-2026-24128XWiki Affected by Reflected Cross-Site Scripting (XSS) in Error Messages6.1
- CVE-2025-66473XWiki's REST APIs don't enforce any limits, leading to unavailability and OOM in large wikis7.5
- CVE-2025-66472XWiki vulnerable to a reflected XSS via xredirect parameter in DeleteApplication6.1
- CVE-2025-55749The XWiki Jetty package (XJetty) allows accessing any application file through URL7.5
- CVE-2025-52472XWiki Platform vulnerable to HQL injection via wiki and space search REST API9.8
- CVE-2025-55748XWiki Platform's configuration files can be accessed through jsx and sx endpoints7.5
- CVE-2025-55747XWiki Platform's configuration files can be accessed through the webjars API9.1
- CVE-2025-58049XWiki PDF export jobs store sensitive cookies unencrypted in job statuses5.8
- CVE-2025-54125XWiki Platform: Password and email exposure in xml.vm fields6.5
- CVE-2025-54124XWiki Platform: Any user with editing rights can access password properties through Database List Properties6.5
- CVE-2025-32430XWiki Platform contains Reflected XSS vulnerability in two templates6.1
Product normalization is registry-driven with AI assist and human review. How it works