Skip to content
Threat Feed

Tag

Xwiki

5 briefs RSS
high advisory

XWiki Platform Old Core Path Traversal via /skin/ Endpoint (CVE-2026-34151)

An attacker can exploit CVE-2026-34151, a path traversal vulnerability in XWiki Platform Old Core through the `/skin/` action endpoint when hosted on Jetty 12+. This allows unauthenticated users to craft URLs to access and download arbitrary files on the server, such as `/etc/passwd` or sensitive XWiki configuration files (e.g., `xwiki.cfg`), potentially leading to information disclosure and further system compromise.

XWiki Platform Old Core +2 path-traversal web-vulnerability xwiki jetty cve information-disclosure platform:network
1r 3t 2i
critical advisory

XWiki Pro Macros Remote Code Execution via Excerpt-Include Macro (CVE-2026-44179)

A critical vulnerability, CVE-2026-44179, exists in XWiki Pro Macros versions before 1.14.5, allowing remote code execution for any user with page editing rights due to improper escaping of page titles and content processed by the excerpt-include macro, leading to XWiki syntax injection and full compromise of the XWiki installation.

xwiki-pro-macros xwiki rce vulnerability java web-application
1t
high advisory

XWiki Platform Livetable Vulnerability Allows Password Hash Reconstruction

A vulnerability in XWiki Platform allows an attacker to reconstruct password hashes using 768 requests through the `LiveTableResults` macro, impacting versions prior to 18.0.0RC1, 17.10.13, 17.4.9, and 16.10.17.

XWiki Platform xwiki credential-access password-hash-disclosure cve-2026-48048
1r
medium advisory

XWiki Multiple Vulnerabilities Allow File Manipulation and Information Disclosure

An authenticated remote attacker can exploit multiple vulnerabilities in XWiki to manipulate files and disclose information.

XWiki vulnerability file-manipulation information-disclosure
2r 2t
high advisory

XWiki Remote Code Execution via Unprotected Velocity Scripting API

XWiki is vulnerable to remote code execution due to an improperly protected scripting API, allowing users with script rights to bypass the Velocity scripting API sandbox and execute arbitrary code, leading to full instance compromise.

xwiki rce velocity scripting CVE-2026-33229
2r 2t