<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T04:51:34.364383+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-207087</id>
    <title>EUVD-2026-207087</title>
    <updated>2026-10-04T04:51:34.423188+00:00</updated>
    <content>EUVD-2026-207087</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-207087"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-55879</id>
    <title>fkie_cve-2024-55879</title>
    <updated>2026-10-04T04:51:34.423235+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>XWiki Platform is a generic wiki platform. Starting in version 2.3 and prior to versions 15.10.9, 16.3.0, any user with script rights can perform arbitrary remote code execution by adding instances of `XWiki.ConfigurableClass` to any page. This compromises the confidentiality, integrity and availability of the whole XWiki installation. This has been patched in XWiki 15.10.9 and 16.3.0. No known workarounds are available except upgrading.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-55879"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r279-47wg-chpr</id>
    <title>GHSA-r279-47wg-chpr — XWiki allows RCE from script right in configurable sections</title>
    <updated>2026-10-04T04:51:34.423271+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.xwiki.platform:xwiki-platform-administration-ui</p>
<p>### Impact
Any user with script rights can perform arbitrary remote code execution by adding instances of `XWiki.ConfigurableClass` to any page. This compromises the confidentiality, integrity and availability of the whole XWiki installation.</p>
<p>To reproduce on a instance, as a user with script rights, edit your user profile and add an object of type `XWiki.ConfigurableClass` ("Custom configurable sections").
Set "Display in section" and "Display in category" to `other`, "Scope" to `Wiki and all spaces` and "Heading" to:
```
#set($codeToExecute = 'Test') #set($codeToExecuteResult = '{{async}}{{groovy}}services.logging.getLogger("attacker").error("Attack from Heading succeeded!"){{/groovy}}{{/async}}')
```
Save the page and view it, then add `?sheet=XWiki.AdminSheet&amp;viewer=content&amp;section=other` to the URL.
If the logs contain "attacker - Attack from Heading succeeded!", then the instance is vulnerable.</p>
<p>### Patches
This has been patched in XWiki 15.10.9 and 16.3.0.</p>
<p>### Workarounds
We're not aware of any workaround except upgrading.</p>
<p>### References
* https://jira.xwiki.org/browse/XWIKI-21207
* https://github.com/xwiki/xwiki-platform/commit/8493435ff9606905a2d913607d6c79862d0c168d</p>
<p>### For more information</p>
<p>If you have any questions or comments about this advisory:
* Open an issue in [Jira XWiki.org](https://jira.xwiki.org/)
* Email us at [Security Mailing List](mailto:security@xwiki.org)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r279-47wg-chpr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3695</id>
    <title>WID-SEC-W-2024-3695 — xwiki: Mehrere Schwachstellen</title>
    <updated>2026-10-04T04:51:34.423312+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in xwiki ausnutzen, um beliebigen Programmcode auszuführen oder Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-3695"/>
  </entry>
</feed>
