Export - CSV (All fields)
Export - CSV (Current fields)
XWIKI-20854
Reflected XSS in the create document form if name validation is enabledXWIKI-20852
Groovy jobs check the wrong author, allowing remote code executionXWIKI-20851
CSRF in the job schedulerXWIKI-20849
CSRF privilege escalation/RCE via the create actionXWIKI-20848
Velocity execution without script right through VelocityCode propertyXWIKI-20847
Velocity execution without script right through VelocityWiki propertyXWIKI-20818
Cookies are sent to external images in rendered diff (and server side request forgery)XWIKI-20817
The diff displays deleted revisions without additional right checkXWIKI-20746
Privilege escalation (PR) from account through Menu.UIExtensionSheetXWIKI-20715
Arbitrary server side file writing from account through office converterXWIKI-20685
No extra right check in script API when accessing deleted documentsXWIKI-20684
Comments of deleted documents can be viewed through REST APIXWIKI-20625
Velocity execution without script right through tree macroXWIKI-20624
Privilege escalation from script right to programming right through title displayerXWIKI-20611
Privilege escalation (PR) from account through like LiveTableResultsXWIKI-20610
Privilege escalation (PR) from account through NotificationRSSServiceXWIKI-20594
Upgrading doesn't prevent exploiting vulnerable XWiki documentsXWIKI-20524
Privilege escalation (PR) from edit right to programming right through icon themesXWIKI-20457
Privilege escalation (PR) from view right via SkinsCode.XWikiSkinsSheetXWIKI-20456
Privilege escalation (PR) from view right on XWiki.ClassSheetXWIKI-20449
Server side request forgery (SSRF) with the Office ViewerXWIKI-20423
Privilege escalation (PR)/RCE from account through AWM view sheetXWIKI-20421
Privilege escalation (PR)/RCE from account through Invitation subject/messageXWIKI-20394
Async and display macro allow displaying and interacting with any document in restricted modeXWIKI-20386
CSRF privilege escalation/RCE via the edit actionXWIKI-20385
Privilege escalation/RCE via the edit actionXWIKI-20373
Privilege escalation via properties with wiki syntax that are executed with the wrong authorXWIKI-20327
Privilege escalation (PR) from account through XWiki syntax injection in cleaned HTML macroXWIKI-20313
Privilege escalation (PR) from account through UIX and cleaned HTML macrosXWIKI-20306
Privilege escalation (PR) from account through IncludedDocuments panelXWIKI-20297
Privilege escalation (PR) from view right on WikiManager.DeleteWikiXWIKI-20295
Privilege escalation (PR) from account through XWiki.SchedulerJobSheetXWIKI-20294
Privilege escalation (PR) from account through PanelsCode.ApplicationsPanelConfigurationSheetXWIKI-20293
Privilege escalation (PR) from account through IncludedPagesDocumentInformation panelXWIKI-20291
CSRF RCE vulnerability in the logger level configurationXWIKI-20290
Stored XSS via the user account and displaycontent/rendercontent templateXWIKI-20287
Privilege escalation (PR) from view right on XWiki.Notifications.Code.LegacyNotificationAdministrationXWIKI-20285
Privilege escalation (PR) from view right via Invitation applicationXWIKI-20283
Privilege escalation (PR) from view right using Invitation.InvitationCommonXWIKI-20281
Privilege escalation (PR) from account through TipsPanelXWIKI-20280
Privilege escalation (PR) from account through FlamingoThemesCode.WebHomeSheetXWIKI-20279
Privilege escalation (PR) from view right on FlamingoThemesCode.WebHomeXWIKI-20276
Stored XSS via the timezone displayer in user profileXWIKI-20275
Privilege escalation (PR) from view right on XWiki.AttachmentSelectorXWIKI-20268
Privilege escalation (PR) from account through AdminTemplatesSheetXWIKI-20267
Privilege escalation (PR) from account through AdminImportSheet/importinline.vmXWIKI-20261
Privilege escalation (PR) from account/view through AdminFieldsDisplaySheet and admin.vmXWIKI-20260
Privilege escalation (PR) from account/view through VFS Tree macroXWIKI-20259
Privilege escalation (PR) from account/view through Notification Preferences MacrosXWIKI-20258
Privilege escalation (PR) from account/view through the Legacy ActivityMacro
{"errorMessages":["You are not authorised to perform this operation. Please log in."],"errors":{}}
[{"id":-1,"name":"My open issues","jql":"assignee = currentUser() AND resolution = Unresolved order by updated DESC","isSystem":true,"sharePermissions":[],"requiresLogin":true},{"id":-2,"name":"Reported by me","jql":"reporter = currentUser() order by created DESC","isSystem":true,"sharePermissions":[],"requiresLogin":true},{"id":-4,"name":"All issues","jql":"order by created DESC","isSystem":true,"sharePermissions":[],"requiresLogin":false},{"id":-5,"name":"Open issues","jql":"resolution = Unresolved order by priority DESC,updated DESC","isSystem":true,"sharePermissions":[],"requiresLogin":false},{"id":-9,"name":"Done issues","jql":"statusCategory = Done order by updated DESC","isSystem":true,"sharePermissions":[],"requiresLogin":false},{"id":-3,"name":"Viewed recently","jql":"issuekey in issueHistory() order by lastViewed DESC","isSystem":true,"sharePermissions":[],"requiresLogin":false},{"id":-6,"name":"Created recently","jql":"created >= -1w order by created DESC","isSystem":true,"sharePermissions":[],"requiresLogin":false},{"id":-7,"name":"Resolved recently","jql":"resolutiondate >= -1w order by updated DESC","isSystem":true,"sharePermissions":[],"requiresLogin":false},{"id":-8,"name":"Updated recently","jql":"updated >= -1w order by updated DESC","isSystem":true,"sharePermissions":[],"requiresLogin":false}]
0.3
0