pkg:Maven/org.xwiki.platform:xwiki-platform-oldcore
45 total CVEsCRITICAL11HIGH11MEDIUM14LOW1
✅ Check your installed version
All known vulnerabilities
- >= 6.4-milestone-1, < 14.10.19
- CRITICAL9.9CVE-2024-31981XWiki Platform: Privilege escalation (PR) from user registration through PDFClass>= 3.0.1, < 14.10.20
- >= 2.0, < 14.10.7
- CRITICAL9.9CVE-2023-29526XWiki Platform's async and display macro allow displaying and interacting with any document in restricted mode>= 10.11.1, < 13.10.11
- CRITICAL9.9CVE-2023-29523XWiki Platform vulnerable to code injection in display method used in user profiles>= 3.3-milestone-1, < 13.10.11
- CRITICAL9.9CVE-2023-26474XWiki Platform vulnerable to privilege escalation via properties with wiki syntax that are executed with wrong author>= 13.10, < 13.10.11
- CRITICAL9.6CVE-2023-46242XWiki Platform vulnerable to remote code execution via the edit action because it lacks CSRF token>= 1.0, < 14.10.7
- from 0, < 12.6.3
- CRITICAL9.1CVE-2023-29507org.xwiki.platform:xwiki-platform-oldcore makes Incorrect Use of Privileged APIs with DocumentAuthors>= 14.5, < 14.10
- >= 1.1.2, < 14.10.21
- >= 13.4.7, < 14.10.21
- HIGH8.8CVE-2023-46243XWiki Platform vulnerable to privilege escalation and remote code execution via the edit action>= 15.0, < 15.2-rc-1
- from 0, < 11.10.6
- HIGH8.4CVE-2023-35157XWiki Platform vulnerable to reflected cross-site scripting via delattachment action>= 3.2-milestone-3, < 14.10.6
- >= 1.8-rc-1, < 16.10.16
- HIGH8.1CVE-2022-31166XWiki.WebHome vulnerable to Improper Privilege Management in XWiki resolving groups>= 11.3.7, < 13.10.4
- >= 1.1, < 13.10.5
- >= 1.0, < 14.10.17
- HIGH8.0CVE-2023-40572XWiki Platform vulnerable to CSRF privilege escalation/RCE via the create action>= 3.2-milestone-3, < 14.10.9
- HIGH7.5CVE-2023-29208org.xwiki.platform:xwiki-platform-oldcore vulnerable to data leak through deleted documents>= 1.2-milestone-1, < 13.10.11
- from 0, < 13.10.8
- HIGH7.5CVE-2022-36092XWiki Platform Old Core vulnerable to Authentication Bypass Using the Login Actionfrom 0, < 13.10.4
- MEDIUM6.8CVE-2024-31464XWiki Platform: Password hash might be leaked by diff once the xobject holding them is deleted>= 5.0-rc-1, < 14.10.19
- from 0, < 11.10.5
- MEDIUM6.5CVE-2023-37911org.xwiki.platform:xwiki-platform-oldcore may leak data through deleted and re-created documents>= 9.4-rc-1, < 14.10.8
- from 0, < 12.10.6
- MEDIUM6.3CVE-2023-41046Velocity execution without script right through VelocityCode and VelocityWiki property>= 7.2, < 14.10.10
- from 0, < 14.0-rc-1
- >= 13.6-rc-1, < 13.7-rc-1
- >= 1.0, < 13.0
- MEDIUM4.9CVE-2022-41929Missing Authorization in User#setDisabledStatus in org.xwiki.platform:xwiki-platform-oldcore>= 11.7RC1, < 13.10.7
- from 0, < 14.10.4
- >= 6.0-rc-1, < 13.10.10
- from 0, < 12.10.7
- >= 13.10.4, < 14.10.21
- from 0, < 12.10.6
- >= 8.3-rc-1, < 13.10.3
- —CVE-2026-33229XWiki vulnerable to remote code execution with script right through unprotected Velocity scripting API>= 17.0.0-rc-1, < 17.4.8
- —CVE-2025-54125XWiki exposes passwords and emails stored in fields not named password/email in xml.vm>= 1.1, < 16.4.7
- >= 9.8-rc-1, < 16.4.7
- >= 1.0, < 16.10.6
- >= 7.2-milestone-2, < 16.4.7
- >= 1.0, < 15.10.16
- —CVE-2025-32968org.xwiki.platform:xwiki-platform-oldcore allows SQL injection in short form select requests through the script query API>= 1.6-milestone-1, < 15.10.16
- >= 0.9.543, < 1.0B1