Loading HuntDB...

XWiki Platform

315 Versions 188 CVEs

Versions

>= 7.2, < 11.10.3

OTHER 1 CVE

>= 7.2-milestone-2, < 14.10.12

OTHER 1 CVE

>= 14.0.0, < 14.4.1

OTHER 1 CVE

>= 6.2-milestone-1, < 14.10.5

OTHER 1 CVE

>= 11.8-rc-1, < 15.10.8

RC 1 CVE

>= 16.0.0-rc-1, < 16.4.1

RC 1 CVE

>= 5.0-rc-1, < 14.10.19

RC 1 CVE

>= 13.0.0, < 13.4.7

OTHER 2 CVEs

>= 13.6.0, < 13.6RC1

RC 1 CVE

>= 11.4.0, < 11.10.11

OTHER 1 CVE

>= 2.6-rc-2, < 14.4.8

RC 1 CVE

< 14.6-rc-1

RC 1 CVE

>= 14.0-rc-1, < 14.4-rc-1

RC 1 CVE

>= 1.5-milestone-2, < 15.0-rc-1

RC 1 CVE

>= 14.6, < 14.10

OTHER 1 CVE

>= 1.1, < 13.10.5

OTHER 1 CVE

>= 2.4-m-2, < 14.4.8

OTHER 1 CVE

>= 3.1-milestone-2, < 13.4-rc-1

RC 1 CVE

>= 15.0-rc-1, < 15.5.3

RC 3 CVEs

>= 13.10.4, < 14.0-rc-1

RC 1 CVE

>= 3.5-milestone-1, < 14.10.8

OTHER 1 CVE

>= 2.6.1, < 12.10.11

OTHER 1 CVE

>= 15.0-rc-1, < 15.2

RC 1 CVE

>= 14.0, < 14.3

OTHER 2 CVEs

2.5m1

OTHER 1 CVE

org.xwiki.platform:xwiki-platform-web >= 2.2.1, < 14.4.8

OTHER 1 CVE

< 12.6.3

OTHER 1 CVE

< 15.10-rc-1

RC 1 CVE

>= 13.0, < 13.2RC1

RC 1 CVE

org.xwiki.platform:xwiki-platform-administration-ui:>= 15.0-rc-1, < 15.5.1

RC 1 CVE

>= 10.11.1, < 13.10.11

OTHER 1 CVE

>= 13.0, <= 13.1

OTHER 1 CVE

>= 4.3-milestone-2, < 14.10.20

OTHER 1 CVE

>= 15.0-rc-1, < 15.5.4

RC 11 CVEs

>= 5.0, < 12.10.11

OTHER 1 CVE

>= 1.3, < 13.10.4

OTHER 1 CVE

9.7-rc-1

RC 1 CVE

>= 14.0, < 14.4.7

OTHER 3 CVEs

>= 12.10.0, < 12.10.3

OTHER 1 CVE

>= 1.3-rc-1, < 13.10.11

RC 1 CVE

< 14.10.4

OTHER 1 CVE

>= 14.3-rc-1, < 14.4.6

RC 1 CVE

>= 14.5.0, < 14.10.3.

OTHER 1 CVE

>= 11.3.7, < 13.10.4

OTHER 1 CVE

org.xwiki.platform:xwiki-platform-administration:< 14.10.14

OTHER 1 CVE

>= 15.0-rc-1, < 15.2-rc-1

RC 3 CVEs

< 13.10.8

OTHER 3 CVEs

>= 14.0-rc-1, < 14.4.6

RC 1 CVE

>= 15.0, < 15.5.5

OTHER 1 CVE

>= 13.0.0, < 13.4.1

OTHER 1 CVE

14.0-rc-1

RC 2 CVEs

12.0-rc-1

RC 1 CVE

15.10.1

SEMANTIC 1 CVE

>= 1.7, < 13.10.6

OTHER 1 CVE

>= 14.0-rc-1, < 14.4.4

RC 1 CVE

>= 14.0-rc-1, < 14.4.3

RC 1 CVE

>= 1.2-milestone-1, < 13.10.11

OTHER 1 CVE

org.xwiki.platform:xwiki-platform-web-templates >= 14.5, < 14.10.5

OTHER 1 CVE

>= 7.2, < 14.10.10

OTHER 1 CVE

>= 4.3-milestone-2, < 14.10.5

OTHER 1 CVE

>= 3.0-milestone-1, < 14.9-rc-1

RC 1 CVE

>= 1.5M2, < 13.10.11

OTHER 1 CVE

>= 15.0-rc-1, < 15.1

RC 3 CVEs

> 11.6RC1, < 12.6.8

RC 1 CVE

>= 3.0-milestone-1, < 13.10.10

OTHER 1 CVE

org.xwiki.platform:xwiki-platform-administration-ui:< 14.10.14

OTHER 1 CVE

< 14.10.3

OTHER 1 CVE

>= 14.5.0, < 14.10.3

OTHER 2 CVEs

>= 16.5.0, < 16.6.0-rc-1

RC 1 CVE

>= 12.4, < 13.10.7

OTHER 1 CVE

>= 15.6-rc-1, < 15.6

RC 1 CVE

>= 5.4.4, <= 6.0-milestone-2

OTHER 1 CVE

15.6-rc-1

RC 3 CVEs

>= 13.5.0, < 13.10.9

OTHER 1 CVE

>= 16.0.0-rc-1, < 16.3.0

RC 3 CVEs

>= 1.0, < 14.10.6

OTHER 1 CVE

>= 8.0-rc-1, < 13.10.5

RC 1 CVE

>= 14.0, < 14.4

OTHER 3 CVEs

>= 2.4-milestone-1, < 14.10.20

OTHER 1 CVE

org.xwiki.contrib:application-ckeditor-ui:>= 1.9, < 1.64.9

OTHER 1 CVE

>= 12.7.0, < 12.8-rc-1

RC 1 CVE

>= 13.10.8, < 13.10.11

OTHER 1 CVE

>= 9.7-rc-1, < 15.10.11

RC 1 CVE

2.4-milestone-1

OTHER 1 CVE

>= 14.4.3, < 14.4.7

OTHER 1 CVE

< 14.0-rc-1

RC 1 CVE

> 3.1M1, < 13.1RC1

RC 1 CVE

>= 1.3

OTHER 1 CVE

< 12.10.6

OTHER 2 CVEs

>= 15.6-rc-1, < 15.7-rc-1

RC 5 CVEs

>= 11.7RC1, < 13.10.7

RC 1 CVE

org.xwiki.platform:xwiki-platform-ckeditor-ui:>= 15.0, < 15.1

OTHER 1 CVE

>= 6.2-rc-1, < 13.6

RC 1 CVE

15.0.0

SEMANTIC 2 CVEs

>= 7.2-rc-1, < 13.10.11

RC 1 CVE

>= 13.0.0, < 13.4.3

OTHER 1 CVE

>= 8.3-rc-1, < 14.10.7

RC 1 CVE

>= 14.5.0, < 14.10.1

OTHER 7 CVEs

< 14.10.21

OTHER 1 CVE

>= 12.6.4, < 12.8

OTHER 1 CVE

< 13.10.6

OTHER 1 CVE

>= 9.6-rc-1, < 14.10.6

RC 1 CVE

>= 13.0, < 13.4.6

OTHER 1 CVE

0

SINGLE_NUMBER 2 CVEs

>= 12.6.0, < 12.6.7

OTHER 1 CVE

>= 11.10.1, < 14.10.15

OTHER 1 CVE

org.xwiki.platform:xwiki-platform-ckeditor-ui:>= 14.6-rc-1, < 14.10.6

RC 1 CVE

< 8.4.5, < 10.11.8, < 11.3.1, < 13.6-rc-1

RC 1 CVE

>= 14.5.0, < 14.6

OTHER 1 CVE

15.6.0

SEMANTIC 2 CVEs

>= 16.0.0-rc-1, < 16.0.0

RC 2 CVEs

>= 15.0-rc-1, < 15.4-rc-1

RC 3 CVEs

>= 14.0.0, < 14.7-rc-1

RC 1 CVE

>= 3.0.1, < 14.10.20

OTHER 1 CVE

>= 6.4-milestone-1, < 14.10.19

OTHER 1 CVE

>= 1.0, < 14.10.7

OTHER 1 CVE

15.5.5

SEMANTIC 1 CVE

>= 3.2-milestone-3, < 14.10.9

OTHER 1 CVE

>= 16.0.0-rc-1, < 16.3.0-rc-1

RC 2 CVEs

>= 13.10.0, < 13.10.3

OTHER 1 CVE

>= 3.3-milestone-1, < 13.10.11

OTHER 1 CVE

>= 1.1-M2, < 13.10.11

OTHER 1 CVE

>= 9.2-rc-1, < 14.10.21

RC 1 CVE

>= 14.0-rc-1, < 14.4.7

RC 10 CVEs

>= 11.6-rc-1, < 13.10.10

RC 1 CVE

>= 4.2-milestone-3, < 14.10.21

OTHER 1 CVE

>= 16.0.0, < 16.4.1

OTHER 1 CVE

>= 15.6-rc-1, < 15.10.6

RC 3 CVEs

>= 13.1RC1, < 13.10.8

RC 1 CVE

>= 14.0.0, < 14.4.8

OTHER 10 CVEs

3.1-milestone-2

OTHER 1 CVE

1.8.0,

OTHER 1 CVE

>= 6.3-milestone-2, < 14.10.15

OTHER 1 CVE

>= 13.10, < 13.10.1

OTHER 1 CVE

>= 15.0, < 15.2-rc-1

RC 1 CVE

>= 14.5.0, < 14.10.6

OTHER 1 CVE

>= 2.0, < 14.10.7

OTHER 1 CVE

>= 3.2-milestone-3, < 14.10.7

OTHER 1 CVE

>= 1.0, < 13.10.6

OTHER 1 CVE

>= 13.2-rc-1, < 14.10.21

RC 2 CVEs

>= 5.1-rc-1, < 14.10.8

RC 1 CVE

< 14.10.1

OTHER 1 CVE

>= 14.0, < 14.3-rc-1

RC 2 CVEs

>= 14.5.0, < 14.10.0-rc-1

RC 1 CVE

>= 5.0-milestone-1, < 14.4.8

OTHER 1 CVE

>= 3.5-milestone-1, < 14.10.9

OTHER 1 CVE

14.10.21

SEMANTIC 1 CVE

>= 2.2-milestone-1, < 13.10.6

OTHER 1 CVE

1.3

MAJOR_MINOR 1 CVE

15.0-rc-1

RC 6 CVEs

>= 13.0.0, < 13.3RC1

RC 1 CVE

>= 14.0-rc-1, < 14.2-rc-1

RC 1 CVE

>= 15.6-rc-1, < 15.8-rc-1

RC 3 CVEs

>= 1.1-milestone-3, < 13.10.11

OTHER 1 CVE

>= 14.5, < 14.10

OTHER 13 CVEs

org.xwiki.platform:xwiki-platform-web-templates >= 15.0-rc-1, < 15.1-rc-1

RC 1 CVE

< 12.6.7

OTHER 1 CVE

>= 15.0-rc-0, < 15.1-rc-1

RC 1 CVE

>= 14.0, < 14.3-RC-1

RC 1 CVE

>= 15.0-rc-0, < 15.1

RC 1 CVE

>= 12.10.11, < 13.10.8

OTHER 1 CVE

16.0.0-rc-1

RC 2 CVEs

>= 2.2, < 14.10.17

OTHER 1 CVE

>= 6.1-rc-1, < 14.10.5

RC 1 CVE

>= 13.9-rc-1, < 15.10.12

RC 1 CVE

< 14.10.19

OTHER 1 CVE

>= 14.0.0, < 14.4.7

OTHER 2 CVEs

>= 1.8, < 14.10.8

OTHER 1 CVE

>= 6.2-milestone-1, < 13.10.10

OTHER 1 CVE

>= 13.1RC1, <= 13.1

RC 1 CVE

>= 9.4-rc-1, < 14.10.8

RC 1 CVE

>= 15.0-rc-1, < 15.5-rc-1

RC 4 CVEs

>= 14.5, < 14.7-rc-1

RC 1 CVE

>= 2.4-milestone-2, < 3.1-milestone-1

OTHER 1 CVE

< 14.10.9

OTHER 1 CVE

>= 6.4-milestone-2, < 13.10.7

OTHER 1 CVE

>= 3.2-m3, < 13.4.4

OTHER 1 CVE

15.0

MAJOR_MINOR 1 CVE

< 14.10.15

OTHER 1 CVE

>= 1.0, < 14.10.17

OTHER 1 CVE

>= 2.3-milestone-1, < 13.10.11

OTHER 1 CVE

>= 15.6-rc-1, < 15.9-rc-1

RC 2 CVEs

< 13.10.11

OTHER 9 CVEs

>= 15.0-rc-1, < 15.3-rc-1

RC 3 CVEs

6.4-milestone-1

OTHER 1 CVE

>= 15.0, < 15.3-rc-1

RC 1 CVE

< 14.4.8

OTHER 2 CVEs

>= 6.0-milestone-2, < 12.10.11

OTHER 1 CVE

>= 1.8, <= 3.0.1

OTHER 1 CVE

3.1-milestone-1

OTHER 1 CVE

>= 15.0-rc-1, < 15.1-rc-1

RC 6 CVEs

>= 3.3-milestone-3, < 14.10.4

OTHER 1 CVE

>= 14.0, < 14.2

OTHER 2 CVEs

>= 15.6-rc-1, < 15.10-rc-1

RC 6 CVEs

>= 5.3-milestone-2, < 13.10.6

OTHER 1 CVE

>= 9.7-rc-1, < 14.10.14

RC 1 CVE

>= 10.9, < 13.10.11

OTHER 1 CVE

>= 8.1, < 13.10.8

OTHER 1 CVE

>= 3.2-milestone-2, < 13.10.7

OTHER 1 CVE

>= 14.4.0, < 14.4-rc-1

RC 1 CVE

>= 7.2-rc-1, < 14.10.20

RC 1 CVE

>= 2.5-m1, < 14.4.8

OTHER 1 CVE

>= 14.5, < 14.9-rc-1

RC 3 CVEs

2.4-milestone-2

OTHER 1 CVE

>= 13.4.7, <= 13.5

OTHER 1 CVE

>= 1.2-milestone-2, < 15.10.9

OTHER 1 CVE

>= 15.0-rc-1, < 15.5.5

RC 4 CVEs

>= 9.4-rc-1, < 14.10.5

RC 1 CVE

>=12.0.0, <12.2.1

OTHER 1 CVE

>= 15.0.0, < 15.5.5

OTHER 2 CVEs

>= 4.5-rc-1, < 14.10.15

RC 1 CVE

>= 12.0-rc-1, < 14.10.12

RC 1 CVE

>= 3.1, < 14.10.19

OTHER 2 CVEs

>= 15.0-rc-1, < 15.0

RC 1 CVE

= 16.0.0-rc-1

RC 1 CVE

>= 13.9-rc-1, < 14.10.19

RC 1 CVE

>= 6.3-milestone-2, < 13.10.11

OTHER 1 CVE

>= 3.2-milestone-3, < 14.10.6

OTHER 1 CVE

>= 13.10, < 13.10.11

OTHER 1 CVE

>= 14.5, < 14.9

OTHER 4 CVEs

>= 7.2-milestone-2, < 14.10.15

OTHER 1 CVE

>= 8.1-milestone-1, < 14.10.5

OTHER 1 CVE

org.xwiki.platform:xwiki-platform-web-templates < 14.4.8

OTHER 1 CVE

>= 14.0-rc-1, < 14.4.8

RC 3 CVEs

>= 14.2, < 14.10.21

OTHER 1 CVE

5.0-rc-1

RC 2 CVEs

< 12.10.5

OTHER 2 CVEs

< 11.10.13

OTHER 1 CVE

>= 14.9, < 14.10

OTHER 1 CVE

< 12.9

OTHER 1 CVE

>= 14.4.1, < 14.4.7

OTHER 1 CVE

>= 6.2-milestone-1, < 14.10.6

OTHER 1 CVE

>= 14.5.0, < 14.10.2

OTHER 2 CVEs

14.5.0

SEMANTIC 1 CVE

13.2-rc-1

RC 2 CVEs

>= 13.2-rc-1, < 13.10.11

RC 1 CVE

>= 5.3-milestone-2, < 12.10.11

OTHER 1 CVE

>= 16.5.0-rc-1, < 16.5.0

RC 1 CVE

>= 6.2.4, < 13.10.10

OTHER 1 CVE

>= 13.10.10, < 13.10.11

OTHER 1 CVE

< 13.10.4

OTHER 1 CVE

< 4.3

OTHER 1 CVE

> 3.1M1

OTHER 1 CVE

<11.10.5

OTHER 1 CVE

>= 13.0, < 13.4.7

OTHER 2 CVEs

>= 5.3-milestone-2, < 13.10.11

OTHER 1 CVE

>= 13.0, < 13.3RC1

RC 1 CVE

>= 8.3-rc-1, < 13.10.3

RC 1 CVE

< 12.10.7

OTHER 1 CVE

>= 2.0-milestone-1, < 13.10.5

OTHER 1 CVE

15.0-rc-1,

RC 1 CVE

>= 14.0-rc-1, < 14.3-rc-1

RC 1 CVE

>= 14.0.0, < 14.4.3

OTHER 5 CVEs

>= 13.9-rc-1, < 13.10.8

RC 1 CVE

7.2-milestone-2

OTHER 1 CVE

>= 12.10.0, < 12.10.4

OTHER 1 CVE

>= 14.5, < 14.10.4

OTHER 8 CVEs

>= 13.10.3, < 14.10.21

OTHER 1 CVE

>= 2.2-milestone-1, < 14.4.8

OTHER 1 CVE

>= 14.5, < 14.8-rc-1

RC 2 CVEs

>= 15.6.0, < 15.10.1

OTHER 2 CVEs

>= 4.1-milestone-2, < 14.10.5

OTHER 1 CVE

< 14.8-rc-1

RC 1 CVE

>= 2.3, < 15.10.9

OTHER 1 CVE

>= 2.5-milestone-2, < 14.10.5

OTHER 1 CVE

>= 12.6.6, < 13.10.11

OTHER 1 CVE

>= 14.0-rc-1, < 14.10.12

RC 2 CVEs

>= 14.0-rc-1, < 14.4.5

RC 1 CVE

>= 12.0.0, < 12.6.3

OTHER 1 CVE

>= 6.2.4, < 12.10.11

OTHER 1 CVE

>= 11.8-rc-1, < 14.4.8

RC 1 CVE

>= 5.4.4, < 14.4.8

OTHER 1 CVE

>= 14.5.0, < 14.6-rc-1

RC 2 CVEs

>= 7.3-milestone-1, < 14.4.8

OTHER 1 CVE

>= 13.6.0, < 13.7-rc-1

RC 1 CVE

>= 12.5-rc-1, < 13.10.6

RC 1 CVE

>= 1.9-milestone-2, < 13.10.10

OTHER 1 CVE

>= 5.2-milestone-2, < 14.10.20

OTHER 1 CVE

>= 14.5.0, < 14.10-rc-1

RC 1 CVE

>= 3.4-milestone-1, < 14.10.5

OTHER 1 CVE

< 14.10.2

OTHER 1 CVE

>= 12.9-rc-1, < 14.4.8

RC 1 CVE

>= 7.0-rc-1, < 14.4.8

RC 1 CVE

>= 14.5, < 14.10.6

OTHER 3 CVEs

>= 3.5-milestone-1, < 14.4.8

OTHER 1 CVE

>= 12.10, < 13.10.10

OTHER 1 CVE

>= 3.3-milestone-1, < 15.10.9

OTHER 1 CVE

>= 12.0, < 12.5

OTHER 1 CVE

>= 14.5, < 14.10.1

OTHER 2 CVEs

>= 6.3-milestone-2, < 13.10.5

OTHER 1 CVE

>= 15.6-rc-1, < 15.9

RC 3 CVEs

>= 6.0-rc-1, < 14.10.6

RC 1 CVE

>= 15.6-rc-1, < 15.10.2

RC 2 CVEs

>= 12.10.0, < 12.10.2

OTHER 1 CVE

< 11.10.6

OTHER 1 CVE

>= 1.0, < 13.0

OTHER 1 CVE

>= 14.10, < 14.10.18

OTHER 1 CVE

>= 1.8.0, < 15.10.9

OTHER 1 CVE

>= 13.5.0, < 13.10.3

OTHER 1 CVE

< 12.10.9

OTHER 2 CVEs

>= 4.2-milestone-3, < 13.10.11

OTHER 1 CVE

>= 13.0.0, < 13.2-rc-1

RC 1 CVE

>= 2.3, < 14.10.15

OTHER 2 CVEs

>= 3.1-milestone-1, < 13.4-rc-1

RC 1 CVE

>= 13.5, < 13.10.3

OTHER 2 CVEs

>= 6.0, < 13.10.10

OTHER 1 CVE

>= 14.4, < 14.4.7

OTHER 1 CVE

>= 7.4.4, < 14.10.3

OTHER 1 CVE

>= 14.0, < 14.4.6

OTHER 4 CVEs

>= 15.0-rc-1, < 15.5.1

RC 3 CVEs

>= 14.0.0, < 14.4.2

OTHER 5 CVEs

>= 15.0-rc-1, < 15.5.2

RC 5 CVEs

>= 5.0-milestone-1, < 13.10.7

OTHER 1 CVE

>= 14.0.0, < 14.3.1

OTHER 1 CVE

>= 6.0-rc-1, < 13.10.10

RC 1 CVE

Recent CVEs

CVE-2025-23025

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. NOTE: The Realtime WYSIWYG Editor extension was **experimental**, and thus **not recommended**, in the versions affected by this vulnerability. It has become enabled by default, and thus recommended, starting with XWiki 16.9.0. A user with only **edit right** can join a realtime editing session where others, that where already there or that may join later, have **script** or **programming** access rights. This user can then insert **script rendering macros** that are executed for those users in the realtime session that have script or programming rights. The inserted scripts can be used to gain more access rights. This vulnerability has been patched in XWiki 15.10.2, 16.4.1 and 16.6.0-rc-1. Users are advised to upgrade. Users unable to upgrade may either disable the realtime WYSIWYG editing by disabling the ``xwiki-realtime`` CKEditor plugin from the WYSIWYG editor administration section or uninstall the Realtime WYSIWYG Editorextension (org.xwiki.platform:xwiki-platform-realtime-wysiwyg-ui).

CRITICAL Jan 14, 2025

CVE-2024-55879

XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with script rights can perform arbitrary remote code execution by adding instances of `XWiki.ConfigurableClass` to any page. This compromises the confidentiality, integrity and availability of the whole XWiki installation. This has been patched in XWiki 15.10.9 and 16.3.0. No known workarounds are available except upgrading.

CRITICAL Dec 12, 2024

CVE-2024-55877

XWiki Platform is a generic wiki platform. Starting in version 9.7-rc-1 and prior to versions 15.10.11, 16.4.1, and 16.5.0, any user with an account can perform arbitrary remote code execution by adding instances of `XWiki.WikiMacroClass` to any page. This compromises the confidentiality, integrity and availability of the whole XWiki installation. This vulnerability has been fixed in XWiki 15.10.11, 16.4.1 and 16.5.0. It is possible to manually apply the patch to the page `XWiki.XWikiSyntaxMacrosList` as a workaround.

CRITICAL Dec 12, 2024

CVE-2024-55876

XWiki Platform is a generic wiki platform. Starting in version 1.2-milestone-2 and prior to versions 15.10.9 and 16.3.0, any user with an account on the main wiki could run scheduling operations on subwikis. To reproduce, as a user on the main wiki without any special right, view the document `Scheduler.WebHome` in a subwiki. Then, click on any operation (*e.g.,* Trigger) on any job. If the operation is successful, then the instance is vulnerable. This has been patched in XWiki 15.10.9 and 16.3.0. As a workaround, those who have subwikis where the Job Scheduler is enabled can edit the objects on `Scheduler.WebPreferences` to match the patch.

MEDIUM Dec 12, 2024

CVE-2024-55663

XWiki Platform is a generic wiki platform. Starting in version 6.3-milestone-2 and prior to versions 13.10.5 and 14.3-rc-1, in `getdocument.vm`; the ordering of the returned documents is defined from an unsanitized request parameter (request.sort) and can allow any user to inject HQL. Depending on the used database backend, the attacker may be able to not only obtain confidential information such as password hashes from the database, but also execute UPDATE/INSERT/DELETE queries. This has been patched in 13.10.5 and 14.3-rc-1. There is no known workaround, other than upgrading XWiki.

UNKNOWN Dec 12, 2024

CVE-2024-55662

XWiki Platform is a generic wiki platform. Starting in version 3.3-milestone-1 and prior to versions 15.10.9 and 16.3.0, on instances where `Extension Repository Application` is installed, any user can execute any code requiring `programming` rights on the server. This vulnerability has been fixed in XWiki 15.10.9 and 16.3.0. Since `Extension Repository Application` is not mandatory, it can be safely disabled on instances that do not use it as a workaround. It is also possible to manually apply the patches from commit 8659f17d500522bf33595e402391592a35a162e8 to the page `ExtensionCode.ExtensionSheet` and to the page `ExtensionCode.ExtensionAuthorsDisplayer`.

CRITICAL Dec 12, 2024