Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Majkelstick

#19661of 56,333
14.7Total CVSS
Vulnerabilities · 2
Medium
1
Critical
1
PT-2026-42215
9.3
2026-05-20
Xwiki · Xwiki Platform · CVE-2026-23734
**Name of the Vulnerable Software and Affected Versions** XWiki versions prior to 16.10.17 XWiki versions prior to 17.4.9 XWiki versions prior to 17.10.3 XWiki versions prior to 18.1.0-rc-1 **Description** XWiki Platform allows unauthenticated access to read arbitrary server-side configuration files, such as `WEB-INF/xwiki.cfg`. This is possible through a Path Traversal issue, where an attacker can use leading slashes in the `resource` parameter to escape the intended directory. The issue is specifically exploitable via the `/bin/ssx/` and `/bin/jsx/` endpoints and has been confirmed on Tomcat deployments. **Recommendations** Update to version 16.10.17 Update to version 17.4.9 Update to version 17.10.3 Update to version 18.1.0-rc-1
PT-2025-8690
5.4
2025-02-26
Acquia · Mautic · CVE-2022-25773
**Name of the Vulnerable Software and Affected Versions** The product name cannot be determined. **Description** A file placement issue exists, allowing assets to be uploaded to unintended server directories. This is due to improper limitation of a pathname to a restricted directory, specifically in the asset upload functionality. This enables users to upload files outside of the intended temporary directory. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.