Vulnerability Name CVE Severity
XWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-29515) CVE-2023-29515
XWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-32070) CVE-2023-32070
XWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-34464) CVE-2023-34464
XWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-35153) CVE-2023-35153
XWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-35155) CVE-2023-35155
XWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-35156) CVE-2023-35156
XWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-35157) CVE-2023-35157
XWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-35159) CVE-2023-35159
XWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-35160) CVE-2023-35160
XWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-35161) CVE-2023-35161
XWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-35162) CVE-2023-35162
XWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-36477) CVE-2023-36477
XWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-40176) CVE-2023-40176
XWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-45137) CVE-2023-45137
XWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-46732) CVE-2023-46732
XWiki Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-43400) CVE-2024-43400
XWiki Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2020-15171) CVE-2020-15171
XWiki Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability (CVE-2022-23616) CVE-2022-23616
XWiki Improper Preservation of Permissions Vulnerability (CVE-2021-21379) CVE-2021-21379
XWiki Incorrect Authorization Vulnerability (CVE-2021-32620) CVE-2021-32620
XWiki Incorrect Authorization Vulnerability (CVE-2022-23615) CVE-2022-23615
XWiki Incorrect Authorization Vulnerability (CVE-2023-26056) CVE-2023-26056
XWiki Incorrect Authorization Vulnerability (CVE-2023-50732) CVE-2023-50732
XWiki Incorrect Authorization Vulnerability (CVE-2024-38369) CVE-2024-38369
XWiki Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2021-32729) CVE-2021-32729
XWiki Insufficiently Protected Credentials Vulnerability (CVE-2022-41933) CVE-2022-41933
XWiki Missing Authentication for Critical Function Vulnerability (CVE-2022-24820) CVE-2022-24820
XWiki Missing Authorization Vulnerability (CVE-2022-23617) CVE-2022-23617
XWiki Missing Authorization Vulnerability (CVE-2022-31167) CVE-2022-31167
XWiki Missing Authorization Vulnerability (CVE-2022-41929) CVE-2022-41929
XWiki Missing Authorization Vulnerability (CVE-2023-41046) CVE-2023-41046
XWiki Other Vulnerability (CVE-2022-41935) CVE-2022-41935
XWiki Permissions, Privileges, and Access Controls Vulnerability (CVE-2006-7223) CVE-2006-7223
XWikiplatform Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2024-31985) CVE-2024-31985
XWikiplatform CVE-2025-32972 Vulnerability (CVE-2025-32972) CVE-2025-32972
XWikiplatform Exposure of Private Personal Information to an Unauthorized Actor Vulnerability (CVE-2025-54124) CVE-2025-54124
XWikiplatform Exposure of Private Personal Information to an Unauthorized Actor Vulnerability (CVE-2025-54125) CVE-2025-54125
XWikiplatform Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2024-37900) CVE-2024-37900
XWikiplatform Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-41947) CVE-2024-41947
XWikiplatform Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2025-32430) CVE-2025-32430
XWikiplatform Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2025-51990) CVE-2025-51990
XWikiplatform Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2025-66472) CVE-2025-66472
XWikiplatform Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2026-24128) CVE-2026-24128
XWikiplatform Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Vulnerability (CVE-2026-40105) CVE-2026-40105
XWikiplatform Improper Restriction of Rendered UI Layers or Frames Vulnerability (CVE-2026-26000) CVE-2026-26000
XWikiplatform Missing Authorization Vulnerability (CVE-2024-37898) CVE-2024-37898
XWikiplatform Missing Authorization Vulnerability (CVE-2024-45591) CVE-2024-45591
XWikiplatform Missing Authorization Vulnerability (CVE-2024-55876) CVE-2024-55876
XWikiplatform Missing Authorization Vulnerability (CVE-2025-46554) CVE-2025-46554
XWikiplatform Other Vulnerability (CVE-2024-46978) CVE-2024-46978
XWikiplatform Other Vulnerability (CVE-2024-46979) CVE-2024-46979
XWikiplatform Other Vulnerability (CVE-2025-29925) CVE-2025-29925
XWikiplatform Other Vulnerability (CVE-2025-32783) CVE-2025-32783
XWikiplatform URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2025-32970) CVE-2025-32970
XWikiplatform Use of Password Hash With Insufficient Computational Effort Vulnerability (CVE-2024-31464) CVE-2024-31464
XWiki Transmission of Private Resources into a New Sphere ('Resource Leak') Vulnerability (CVE-2023-38509) CVE-2023-38509
XWiki Uncontrolled Resource Consumption Vulnerability (CVE-2024-21651) CVE-2024-21651
XWiki URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-23618) CVE-2022-23618
XWiki URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-29204) CVE-2023-29204
XWiki URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-32068) CVE-2023-32068
XXE in Ivanti Connect Secure, Policy Secure and Neurons (CVE-2024-22024) CVE-2024-22024
YetiForce CRM Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-4092) CVE-2021-4092
YetiForce CRM Improper Input Validation Vulnerability (CVE-2021-4111) CVE-2021-4111
YetiForce CRM Improper Input Validation Vulnerability (CVE-2021-4117) CVE-2021-4117
YetiForce CRM Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2023-49508) CVE-2023-49508
YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-4107) CVE-2021-4107
YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-4116) CVE-2021-4116
YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-4121) CVE-2021-4121
YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-1340) CVE-2022-1340
YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-2829) CVE-2022-2829
YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-2885) CVE-2022-2885
YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-2890) CVE-2022-2890
YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-2924) CVE-2022-2924
YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-3000) CVE-2022-3000
YetiForce CRM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-3002) CVE-2022-3002