Vulnerability Name CVE Severity
XWiki Out-of-bounds Write Vulnerability (CVE-2023-26470) CVE-2023-26470
XWiki Permissions, Privileges, and Access Controls Vulnerability (CVE-2006-7223) CVE-2006-7223
XWikiplatform Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2025-66473) CVE-2025-66473
XWikiplatform Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2026-40104) CVE-2026-40104
XWikiplatform Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-31985) CVE-2024-31985
XWikiplatform Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-31986) CVE-2024-31986
XWikiplatform Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-31988) CVE-2024-31988
XWikiplatform CVE-2025-32972 Vulnerability (CVE-2025-32972) CVE-2025-32972
XWikiplatform CVE-2025-48063 Vulnerability (CVE-2025-48063) CVE-2025-48063
XWikiplatform CVE-2025-55749 Vulnerability (CVE-2025-55749) CVE-2025-55749
XWikiplatform Exposure of Private Personal Information to an Unauthorized Actor Vulnerability (CVE-2025-54124) CVE-2025-54124
XWikiplatform Exposure of Private Personal Information to an Unauthorized Actor Vulnerability (CVE-2025-54125) CVE-2025-54125
XWikiplatform Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-31465) CVE-2024-31465
XWikiplatform Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-31982) CVE-2024-31982
XWikiplatform Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-31984) CVE-2024-31984
XWikiplatform Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-31996) CVE-2024-31996
XWikiplatform Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-37899) CVE-2024-37899
XWikiplatform Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-37900) CVE-2024-37900
XWikiplatform Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-37901) CVE-2024-37901
XWikiplatform Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-55877) CVE-2024-55877
XWikiplatform Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2025-24893) CVE-2025-24893
XWikiplatform Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2025-49581) CVE-2025-49581
XWikiplatform Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2025-51991) CVE-2025-51991
XWikiplatform Improper Encoding or Escaping of Output Vulnerability (CVE-2024-55663) CVE-2024-55663
XWikiplatform Improper Encoding or Escaping of Output Vulnerability (CVE-2025-32974) CVE-2025-32974
XWikiplatform Improper Input Validation Vulnerability (CVE-2025-54385) CVE-2025-54385
XWikiplatform Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-41947) CVE-2024-41947
XWikiplatform Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2025-32430) CVE-2025-32430
XWikiplatform Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2025-46558) CVE-2025-46558
XWikiplatform Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2025-51990) CVE-2025-51990
XWikiplatform Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2025-53835) CVE-2025-53835
XWikiplatform Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2025-66472) CVE-2025-66472
XWikiplatform Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2026-24128) CVE-2026-24128
XWikiplatform Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Vulnerability (CVE-2026-40105) CVE-2026-40105
XWikiplatform Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2024-56158) CVE-2024-56158
XWikiplatform Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2025-32429) CVE-2025-32429
XWikiplatform Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2025-32968) CVE-2025-32968
XWikiplatform Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2025-32969) CVE-2025-32969
XWikiplatform Improper Removal of Sensitive Information Before Storage or Transfer Vulnerability (CVE-2025-58049) CVE-2025-58049
XWikiplatform Improper Restriction of Rendered UI Layers or Frames Vulnerability (CVE-2026-26000) CVE-2026-26000
XWikiplatform Incorrect Authorization Vulnerability (CVE-2024-55662) CVE-2024-55662
XWikiplatform Incorrect Authorization Vulnerability (CVE-2025-29924) CVE-2025-29924
XWikiplatform Incorrect Authorization Vulnerability (CVE-2025-32971) CVE-2025-32971
XWikiplatform Incorrect Authorization Vulnerability (CVE-2025-49586) CVE-2025-49586
XWikiplatform Incorrect Authorization Vulnerability (CVE-2025-53836) CVE-2025-53836
XWikiplatform Incorrect Privilege Assignment Vulnerability (CVE-2025-49580) CVE-2025-49580
XWikiplatform Insertion of Sensitive Information Into Sent Data Vulnerability (CVE-2025-49584) CVE-2025-49584
XWikiplatform Insufficient UI Warning of Dangerous Operations Vulnerability (CVE-2025-49582) CVE-2025-49582
XWikiplatform Insufficient UI Warning of Dangerous Operations Vulnerability (CVE-2025-49583) CVE-2025-49583
XWikiplatform Insufficient UI Warning of Dangerous Operations Vulnerability (CVE-2025-49585) CVE-2025-49585
XWikiplatform Insufficient UI Warning of Dangerous Operations Vulnerability (CVE-2025-49587) CVE-2025-49587
XWikiplatform Missing Authorization Vulnerability (CVE-2024-31981) CVE-2024-31981
XWikiplatform Missing Authorization Vulnerability (CVE-2024-31983) CVE-2024-31983
XWikiplatform Missing Authorization Vulnerability (CVE-2024-31987) CVE-2024-31987
XWikiplatform Missing Authorization Vulnerability (CVE-2024-31997) CVE-2024-31997
XWikiplatform Missing Authorization Vulnerability (CVE-2024-37898) CVE-2024-37898
XWikiplatform Missing Authorization Vulnerability (CVE-2024-45591) CVE-2024-45591
XWikiplatform Missing Authorization Vulnerability (CVE-2024-55876) CVE-2024-55876
XWikiplatform Missing Authorization Vulnerability (CVE-2024-55879) CVE-2024-55879
XWikiplatform Missing Authorization Vulnerability (CVE-2025-23025) CVE-2025-23025
XWikiplatform Missing Authorization Vulnerability (CVE-2025-29926) CVE-2025-29926
XWikiplatform Missing Authorization Vulnerability (CVE-2025-32973) CVE-2025-32973
XWikiplatform Missing Authorization Vulnerability (CVE-2025-46554) CVE-2025-46554
XWikiplatform Missing Authorization Vulnerability (CVE-2025-46557) CVE-2025-46557
XWikiplatform Missing Authorization Vulnerability (CVE-2026-33229) CVE-2026-33229
XWikiplatform Other Vulnerability (CVE-2024-46978) CVE-2024-46978
XWikiplatform Other Vulnerability (CVE-2024-46979) CVE-2024-46979
XWikiplatform Other Vulnerability (CVE-2025-29925) CVE-2025-29925
XWikiplatform Other Vulnerability (CVE-2025-32783) CVE-2025-32783
XWiki Platform RCE (CVE-2023-37462) CVE-2023-37462
XWikiplatform Relative Path Traversal Vulnerability (CVE-2025-55747) CVE-2025-55747
XWikiplatform Relative Path Traversal Vulnerability (CVE-2025-55748) CVE-2025-55748
XWikiplatform URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2025-32970) CVE-2025-32970
XWikiplatform Use of Password Hash With Insufficient Computational Effort Vulnerability (CVE-2024-31464) CVE-2024-31464
XWiki Server-Side Request Forgery (SSRF) Vulnerability (CVE-2023-48240) CVE-2023-48240