Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Xwiki

First CVE: Dec 31, 2005Active for: 21 yearsTotal CVEs: 282
73.2
VTI Score
TOP TARGET

XWiki is an open-source wiki and collaboration platform whose vulnerability footprint, despite a focused product portfolio, ranks among the most represented in the landscape, reflecting the platform's deep embeddedness in internal knowledge-management and documentation infrastructure. Vulnerabilities affecting the vendor skew strongly toward serious outcomes and frequently acquire public exploit code, driven by the platform's dynamic content-generation model and server-side code execution capabilities. The exposure recurs persistently across XWiki's core product, rendering libraries, and macro subsystems through interconnected weakness classes centered on improper neutralization of user input in dynamically evaluated contexts—cross-site scripting, code injection, eval injection, and missing authorization—that are structural to a wiki platform where users can contribute template-driven content with embedded expressions. Defenders should treat XWiki disclosures as high-priority for any internal wiki deployment and inventory instances that expose the platform to untrusted user submission; live severity, exploit availability, and exploitation activity are shown alongside this summary.

FAUCET AI Generated
282
Total CVEs
More Total CVEs than 100% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.4%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Xwiki over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2005
20 years ago
Most Recent CVE
Apr 30, 2026
85 days ago

Products(19 total)

Top CVEs

Signals from CVEs in this vendor scope (282 CVEs).

282 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-24893CRITICAL
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to
Feb 20, 20259.899YESYES
CVE-2025-32429CRITICAL
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 17.0.0-rc-1 through 17.2.2, it's p
Jul 24, 20259.890NOYES
CVE-2024-21650CRITICAL
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code execution (RCE) attack through its use
Jan 8, 20249.883NOYES
CVE-2025-32969CRITICAL
XWiki is a generic wiki platform. In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possible for a remote unauthenticated user to escape from the HQL
Apr 23, 20259.881NOYES
CVE-2023-37462HIGH
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Improper escaping in the document `SkinsCode.XWikiSkinsSheet` leads to an i
Jul 14, 20238.880NOYES
CVE-2023-46731CRITICAL
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki doesn't properly escape the section URL parameter that is used in the
Nov 6, 20239.878NONO
CVE-2023-50719HIGH
XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password
Dec 15, 20237.575NOYES
CVE-2023-48241HIGH
XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 14.10.15, 15.5.1, and 15.6RC1, the Solr-based search suggestion provider that a
Nov 20, 20237.573NOYES
CVE-2023-35150HIGH
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to versions 14.4.8, 14.10.4, and 15.0
Jun 23, 20238.070NONO
CVE-2023-26477CRITICAL
XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script macro
Mar 2, 20239.870NONO
View all 282 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products282 CVEs
37%
46%
15%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network274 (97.2%)
Unknown8 (2.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low272 (96.5%)
High2 (0.7%)
Unknown8 (2.8%)
User Interaction
None178 (63.1%)
Unknown8 (2.8%)
Required96 (34.0%)
Privileges Required
Low156 (55.3%)
High10 (3.5%)
None108 (38.3%)
Unknown8 (2.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (282 CVEs).

CISA KEV
1 CVE
0.4% of CVEs· 99th percentile
Metasploit
1 CVE
0.4% of CVEs· 97th percentile
Nuclei
36 CVEs
12.8% of CVEs· 97th percentile
ExploitDB
4 CVEs
1.4% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Xwiki.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Xwiki — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Xwiki's Products

View all 3 CNAs →

Top CWEs