VulnSea

xwiki has 7 CVEs on record. Disclosure cadence is accelerating: 4 in the last 90 days against 2 in the 90 before. The busiest recent month was September 2026 with 3. The median CVSS is 9.0 (critical), with 4 rated critical. None have a confirmed exploitation report. Most affected products: xwiki-platform (2), blog_application (1), com.xwiki.pro:xwiki-pro-macros (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.0
Publish → KEV
Last 90 days
4 prev 2

Products

  • xwiki-platform 2
  • blog_application 1
  • com.xwiki.pro:xwiki-pro-macros 1
  • org.xwiki.contrib:discussions-server 1
  • xwiki 1
  • xwiki-rendering 1
7
Total CVEs
4
Critical
0
CISA KEV
0
Exploited

xwiki vulnerabilities

CVEs affecting xwiki, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2025-53837Critical· 9.9
3d ago

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc)

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile o…

Midnightxwiki · xwiki-renderingEPSS 0.64%via NVD
CVE-2026-53966High· 7.1
6d ago

XWiki Platform is a generic wiki platform

XWiki Platform is a generic wiki platform. From 13.4-rc-1 until 16.10.17, 17.4.10, 17.10.4, and 18.1.0-rc-1, the Live Data edit REST API allows a user who can edit a page to change that page's rights without executing the normal document…

Twilightxwiki · xwiki-platformEPSS 0.33%via NVD
CVE-2026-34151High· 8.2
1w ago

XWiki Platform is a generic wiki platform

XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended skin or web-application resource prefix w…

Twilightxwiki · xwiki-platformEPSS 0.54%via NVD
CVE-2023-37465Medium· 6.5
1mo ago

org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages

org.xwiki.contrib:discussions-server has Cross-Site Request Forgery (CSRF) issue that makes it possible to delete messages

Sunlitxwiki · org.xwiki.contrib:discussions-servervia GHSA
CVE-2026-44179Critical· 9.9
3mo ago

xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro

xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro

Midnightxwiki · com.xwiki.pro:xwiki-pro-macrosvia GHSA
CVE-2026-33229Critical· 9.8PoC
5mo ago

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Prior to 17.4.8 and 17.10.1, an improperly protected scripting API allows any user with script right to bypass the sandboxing of the…

Abyssalxwiki · xwikiEPSS 0.54%via NVD
CVE-2025-66024Critical· 9.0PoC
6mo ago

The XWiki blog application allows users of the XWiki platform to create and manage blog posts

The XWiki blog application allows users of the XWiki platform to create and manage blog posts. Versions starting with 9.15 and prior to 9.15.7 are vulnerable to Stored Cross-Site Scripting (XSS) via the Blog Post Title. The vulnerability…

Abyssalxwiki · blog_applicationEPSS 0.36%via NVD
xwiki vulnerabilities (CVEs) · VulnSea