CVE-2025-55747 XWiki Platform’s configuration files can be accessed through the webjars API

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 6.1-milestone-2 through 16.10.6, configuration files are accessible through the we ...

Continue Reading
GHSA-QWW7-89XH-X7M7 XWiki configuration files can be accessed through the webjars API

Impact It's possible to get access and read configuration files by using URLs such as https://localhost:8080/xwiki/webjars/wiki%3Axwiki/..%2F..%2F..%2F..%2F..%2FWEB-INF%2Fxwiki.cfg. The trick here ...

Continue Reading
EUVD-2025-26620

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to upload arbitrary files to an affected device ...

Continue Reading
EUVD-2025-26621

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to obtain sensit ...

Continue Reading
CKEditor 5 cross-site scripting (XSS) vulnerability in the clipboard package

Impact A Cross-Site Scripting (XSS) vulnerability has been discovered in the CKEditor 5 clipboard package. This vulnerability could be triggered by a specific user action, leading to unauthorized Java ...

Continue Reading
XWiki configuration files can be accessed through the webjars API

Impact It's possible to get access and read configuration files by using URLs such as https://localhost:8080/xwiki/webjars/wiki%3Axwiki/..%2F..%2F..%2F..%2F..%2FWEB-INF%2Fxwiki.cfg. The trick here ...

Continue Reading
CVE-2025-55944

creation_timestamp| type| source ---|---|--- 2025-09-03 17:15:06+00:00| seen|...Read More ...

Continue Reading
CVE-2023-49528

creation_timestamp| type| source ---|---|--- 2025-09-03 16:52:34+00:00| seen|...Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: