Количество 3
Количество 3
CVE-2026-33137
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. In versions starting with 15.10.6 and prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17, the POST /wikis/{wikiName} API executes a XAR import without performing any authentication or authorization checks, allowing an unauthenticated attacker to create or update documents in the target wiki. This vulnerability has been patched in XWiki 16.10.17, 17.4.9, 17.10.3, 18.0.1 and 18.1.0-rc-1.
GHSA-qrvh-r3f2-9h4r
XWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName}
BDU:2026-07302
Уязвимость платформы создания совместных веб-приложений XWiki Platform XWiki, связанная с отсутствием авторизации, позволяющая нарушителю создать или изменить произвольные файлы
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-33137 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. In versions starting with 15.10.6 and prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17, the POST /wikis/{wikiName} API executes a XAR import without performing any authentication or authorization checks, allowing an unauthenticated attacker to create or update documents in the target wiki. This vulnerability has been patched in XWiki 16.10.17, 17.4.9, 17.10.3, 18.0.1 and 18.1.0-rc-1. | 1% Низкий | 3 месяца назад | ||
GHSA-qrvh-r3f2-9h4r XWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName} | 1% Низкий | 2 месяца назад | ||
BDU:2026-07302 Уязвимость платформы создания совместных веб-приложений XWiki Platform XWiki, связанная с отсутствием авторизации, позволяющая нарушителю создать или изменить произвольные файлы | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад |
Уязвимостей на страницу