Loading...
Skip to main content
Maven (Java)

org.xwiki.platform:xwiki-platform-oldcore Security Analysis

org.xwiki.platform:xwiki-platform-oldcore has 12 known security vulnerabilities in Maven (Java). Upgrade to version 17.10.1 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.

12 Vulnerabilities

Low Immediate Risk

No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.

Recommended safe version: 17.10.1

Upgrading to 17.10.1 or later resolves all 12 known vulnerabilities in org.xwiki.platform:xwiki-platform-oldcore. Update your pom.xml or build.gradle to version 17.10.1.

Is org.xwiki.platform:xwiki-platform-oldcore in your project?

Check if you're affected and upgrade to 17.10.1 to stay secure.

12
Total
0
Critical
0
High
0
Medium
0
Low

Vulnerabilities

12 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.

CVE / GHSASeverityAffectedFixed In
CVE-2024-56158
XWiki allows SQL injection in query endpoint of REST API with Oracle
CRITICAL
All versions15.10.16, 16.4.7, 16.10.2
CVE-2023-29526
XWiki Platform's async and display macro allow displaying and interacting with any document in restricted mode
CRITICAL
All versions13.10.11, 14.4.8, 14.10.3
CVE-2023-26474
XWiki Platform vulnerable to privilege escalation via properties with wiki syntax that are executed with wrong author
CRITICAL
All versions13.10.11, 14.4.7, 14.10
CVE-2024-31987
XWiki Platform remote code execution from account via custom skins support
CRITICAL
All versions14.10.19, 15.5.4, 15.10-rc-1
CVE-2024-31981
XWiki Platform: Privilege escalation (PR) from user registration through PDFClass
CRITICAL
All versions14.10.20, 15.5.4, 15.10-rc-1
CVE-2023-29523
XWiki Platform vulnerable to code injection in display method used in user profiles
CRITICAL
All versions13.10.11, 14.4.8, 14.10.2
CVE-2024-37899
XWiki Platform allows remote code execution from user account
CRITICAL
All versions14.10.21, 14.10.21, 15.5.5 (+2 more)
CVE-2023-36468
Upgrading doesn't prevent exploiting vulnerable XWiki documents
CRITICAL
All versions14.10.7, 15.2-rc-1
CVE-2024-43400
XWiki Platform allows XSS through XClass name in string properties
CRITICAL
16.0.0-rc-114.10.21, 15.5.5, 15.10.6 (+1 more)
CVE-2023-46242
XWiki Platform vulnerable to remote code execution via the edit action because it lacks CSRF token
CRITICAL
All versions14.10.7, 15.2-rc-1
CVE-2025-49586
XWiki allows remote code execution through preview of XClass changes in AWM editor
HIGH
All versions16.4.7, 16.10.3, 17.0.0
CVE-2026-40104
XWiki's REST APIs can list all pages/spaces, leading to unavailability
MEDIUM
All versions16.10.16, 17.4.8, 17.10.1

About This Data

Vulnerability data for org.xwiki.platform:xwiki-platform-oldcore is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.

CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Check Your Dependencies

Scan your project to check if you're using a vulnerable version of org.xwiki.platform:xwiki-platform-oldcore.

Data from OSV DatabaseUpdated daily200K+ vulnerabilities indexed