Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2025-32429

около 1 года назад

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. It's injected as is as an ORDER BY value. This is fixed in versions 16.10.6 and 17.3.0-rc-1.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-vr59-gm53-v7cq

около 1 года назад

XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter

EPSS: Высокий
fstec логотип

BDU:2025-09129

больше 1 года назад

Уязвимость шаблона getdeleteddocuments.vm платформы создания совместных веб-приложений XWiki Platform XWiki, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-32429

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's possible for anyone to inject SQL using the parameter sort of the getdeleteddocuments.vm. It's injected as is as an ORDER BY value. This is fixed in versions 16.10.6 and 17.3.0-rc-1.

CVSS3: 9.8
85%
Высокий
около 1 года назад
github логотип
GHSA-vr59-gm53-v7cq

XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter

85%
Высокий
около 1 года назад
fstec логотип
BDU:2025-09129

Уязвимость шаблона getdeleteddocuments.vm платформы создания совместных веб-приложений XWiki Platform XWiki, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
85%
Высокий
больше 1 года назад

Уязвимостей на страницу