Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
Maven/org.xwiki.platform:xwiki-platform-legacy-oldcore — 5 CVEs · VulnScope
pkg:Maven/
org.xwiki.platform:xwiki-platform-legacy-oldcore
5 total CVEs
CRITICAL
1
HIGH
1
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.9
CVE-2023-26474
XWiki Platform vulnerable to privilege escalation via properties with wiki syntax that are executed with wrong author
>= 13.10, < 13.10.11
HIGH
8.2
CVE-2026-40104
XWiki's REST APIs can list all pages/spaces, leading to unavailability
>= 1.8-rc-1, < 16.10.16
—
CVE-2026-33229
XWiki vulnerable to remote code execution with script right through unprotected Velocity scripting API
>= 17.0.0-rc-1, < 17.4.8
—
XWiki exposes passwords and emails stored in fields not named password/email in xml.vm
>= 1.1, < 16.4.7
—
XWiki leaks password hashes and other accessible password properties
>= 9.8-rc-1, < 16.4.7
CVE-2025-54125
CVE-2025-54124