📦 Xwiki Rendering

by Xwiki

🔍 What is Xwiki Rendering?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-37908

CRITICAL CVSS 9.0 Oct 25, 2023

CVE-2023-37908 is a cross-site scripting (XSS) vulnerability in XWiki Rendering that allows attackers to inject arbitrary HTML/JavaScript via malicious links. When exploited against privileged users w...

CVE-2023-37912

CRITICAL CVSS 9.9 Oct 25, 2023

This vulnerability in XWiki's footnote macro allows privilege escalation from a standard user account to programming rights, leading to remote code execution. When combined with the include macro, att...

CVE-2025-66474

HIGH CVSS 8.8 Dec 10, 2025

CVE-2025-66474 is an HTML injection vulnerability in XWiki Rendering that allows authenticated users to execute arbitrary script macros, leading to remote code execution. Attackers can gain unrestrict...

CVE-2026-24128

MEDIUM CVSS 6.1 Jan 24, 2026

This reflected XSS vulnerability in XWiki Platform allows attackers to craft malicious URLs that execute arbitrary JavaScript in victims' browsers. If victims have administrative or programming rights...