CVE Tools

Xwiki Platform

116 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Xwiki Platform, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Xwiki Platform CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Xwiki Platform CVEs per month
MonthCVEs
2024-100
2024-110
2024-121
2025-010
2025-021
2025-033
2025-0410
2025-051
2025-069
2025-072
2025-085
2025-092
2025-101
2025-110
2025-124
2026-011
2026-021
2026-030
2026-042
2026-051
2026-060
2026-070
2026-080
2026-090

Severity

How the 116 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical6859%
  • High2421%
  • Medium2118%
  • Low33%

Latest CVEs

The 15 most recently published vulnerabilities affecting Xwiki Platform.

  1. CVE-2026-33137XWiki Platform has an Unauthenticated XAR Import via REST /wikis/{wikiName}7.5
  2. CVE-2026-40105XWiki has Reflected Cross-Site Scripting (XSS) in its page history compare functionality6.1
  3. CVE-2026-33229XWiki Platform affected by remote code execution with script right through unprotected Velocity scripting API9.8
  4. CVE-2026-26000XWiki Platform affected by click-jacking through CSS injection in comments6.1
  5. CVE-2026-24128XWiki Affected by Reflected Cross-Site Scripting (XSS) in Error Messages6.1
  6. CVE-2025-66474XWiki vulnerable to remote code execution through insufficient protection against {{/html}} injection8.8
  7. CVE-2025-66473XWiki's REST APIs don't enforce any limits, leading to unavailability and OOM in large wikis7.5
  8. CVE-2025-66472XWiki vulnerable to a reflected XSS via xredirect parameter in DeleteApplication6.1
  9. CVE-2025-55749The XWiki Jetty package (XJetty) allows accessing any application file through URL7.5
  10. CVE-2025-52472XWiki Platform vulnerable to HQL injection via wiki and space search REST API9.8
  11. CVE-2025-55748XWiki Platform's configuration files can be accessed through jsx and sx endpoints7.5
  12. CVE-2025-55747XWiki Platform's configuration files can be accessed through the webjars API9.1
  13. CVE-2025-51991XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, specifically within the HTTP Meta Info field of the Global Preferences Presentat...8.8
  14. CVE-2025-51990XWiki through version 17.3.0 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities in the Administration interface, specifically under the Presentation section of the Global Pre...4.8
  15. CVE-2025-54125XWiki Platform: Password and email exposure in xml.vm fields6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store