CVE security advisories and vulnerability history for xwiki-platform by xwiki.
242
Total CVEs
Published
1
In CISA KEV
Exploited in the wild
131
Public exploits
With known exploit
8.2
Avg CVSS
2018–2026
Last updated
Overview
xwiki xwiki-platform has 242 published CVE records since 2018, of which 1 are in CISA's Known Exploited Vulnerabilities catalog and 131 have a known public exploit. The average CVSS base score across scored CVEs is 8.2.
This page aggregates every publicly disclosed vulnerability (CVE) affecting xwiki xwiki-platform, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of xwiki xwiki-platform's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical116
High64
Medium55
Low5
2 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
1
One of xwiki xwiki-platform's CVEs is confirmed exploited in the wild.
Public exploits
131
131 of xwiki xwiki-platform's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every xwiki xwiki-platform version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about xwiki xwiki-platform vulnerabilities.
How many CVEs does xwiki xwiki-platform have?
xwiki xwiki-platform has 242 published CVE records since 2018.
How many xwiki xwiki-platform CVEs are in CISA KEV?
Yes — 1 of xwiki xwiki-platform's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for xwiki xwiki-platform vulnerabilities?
Yes — 131 of xwiki xwiki-platform's CVEs have a known public exploit.
Which versions of xwiki xwiki-platform are affected?
539 distinct xwiki xwiki-platform versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in xwiki xwiki-platform CVEs?
xwiki xwiki-platform's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-95 (Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')), CWE-862 (Missing Authorization), CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')).
How many critical xwiki xwiki-platform vulnerabilities are there?
xwiki xwiki-platform has 116 critical and 64 high-severity CVEs.
What is the average severity of xwiki xwiki-platform CVEs?
The average CVSS base score across xwiki xwiki-platform's scored CVEs is 8.2.