Export - CSV (All fields)
Export - CSV (Current fields)
XWIKI-22490
The WikiManager REST API allows any user to create wikisXWIKI-22487
Open redirect through HTML conversion request filterXWIKI-22474
The Solr script service doesn't take dropped programming right into accountXWIKI-22462
The lesscss script service allows cache clearing without programming rightXWIKI-22460
No warning when granting XWiki.ComponentClass programming rightXWIKI-22139
Upgrade to dompurify 3.1.1XWIKI-22030
Remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosListXWIKI-22002
The required rights analysis doesn't consider TextAreas with default content typeXWIKI-21890
Remote code execution through the extension sheetXWIKI-21810
XSS through XClass name in string propertiesXWIKI-21663
Scheduler in subwiki allows scheduling operations for any main wiki userXWIKI-21626
XSS through conflict resolutionXWIKI-21611
Disabling a user account changes its author, allowing RCE from user accountXWIKI-21474
Remote code execution from account via SearchSuggestSourceSheetXWIKI-21473
Remote code execution from account via SearchSuggestConfigSheetXWIKI-21472
Remote code execution via DatabaseSearchXWIKI-21471
Remote code execution through space title and Solr space facetXWIKI-21438
Remote code execution from view right on Panels.PanelLayoutUpdateXWIKI-21416
CSRF remote code execution through scheduler job's document referenceXWIKI-21411
Privilege escalation (PR) from edit in multilingual wikis via translationsXWIKI-21337
Privilege escalation (PR) from user registration through PDFClassXWIKI-21335
Privilege escalation (PR) from account through UIExtension parametersXWIKI-21208
Solr search discloses password hashes of all usersXWIKI-21207
RCE from script right in configurable sectionsXWIKI-21200
RCE from account through SearchAdminXWIKI-21194
Remote code execution through class name in configurable sectionXWIKI-21173
RCE via first name in user registrationXWIKI-21167
XSS/CSRF RCE in XWiki.ConfigurableClassXWIKI-21138
Whole content of all documents of all wikis exposed to anybody with view right on Solr suggest serviceXWIKI-21122
Remote code execution/programming rights through document reference with configuration section from edit rightXWIKI-21121
Remote code execution/programming rights through heading of configuration sections with edit rightsXWIKI-21095
RXSS through revision parameter in content menuXWIKI-20962
XSS from account in the create page form via template providerXWIKI-20961
XSS with edit right in the create document form for existing pagesXWIKI-20869
Users can be tricked to execute scripts as the create action doesn't display the page's titleXWIKI-20854
Reflected XSS in the create document form if name validation is enabledXWIKI-20852
Groovy jobs check the wrong author, allowing remote code executionXWIKI-20851
CSRF in the job schedulerXWIKI-20849
CSRF privilege escalation/RCE via the create actionXWIKI-20848
Velocity execution without script right through VelocityCode propertyXWIKI-20847
Velocity execution without script right through VelocityWiki propertyXWIKI-20818
Cookies are sent to external images in rendered diff (and server side request forgery)XWIKI-20817
The diff displays deleted revisions without additional right checkXWIKI-20746
Privilege escalation (PR) from account through Menu.UIExtensionSheetXWIKI-20715
Arbitrary server side file writing from account through office converterXWIKI-20685
No extra right check in script API when accessing deleted documentsXWIKI-20684
Comments of deleted documents can be viewed through REST APIXWIKI-20625
Velocity execution without script right through tree macroXWIKI-20624
Privilege escalation from script right to programming right through title displayerXWIKI-20611
Privilege escalation (PR) from account through like LiveTableResults
{"errorMessages":["You are not authorised to perform this operation. Please log in."],"errors":{}}
[{"id":-1,"name":"My open issues","jql":"assignee = currentUser() AND resolution = Unresolved order by updated DESC","isSystem":true,"sharePermissions":[],"requiresLogin":true},{"id":-2,"name":"Reported by me","jql":"reporter = currentUser() order by created DESC","isSystem":true,"sharePermissions":[],"requiresLogin":true},{"id":-4,"name":"All issues","jql":"order by created DESC","isSystem":true,"sharePermissions":[],"requiresLogin":false},{"id":-5,"name":"Open issues","jql":"resolution = Unresolved order by priority DESC,updated DESC","isSystem":true,"sharePermissions":[],"requiresLogin":false},{"id":-9,"name":"Done issues","jql":"statusCategory = Done order by updated DESC","isSystem":true,"sharePermissions":[],"requiresLogin":false},{"id":-3,"name":"Viewed recently","jql":"issuekey in issueHistory() order by lastViewed DESC","isSystem":true,"sharePermissions":[],"requiresLogin":false},{"id":-6,"name":"Created recently","jql":"created >= -1w order by created DESC","isSystem":true,"sharePermissions":[],"requiresLogin":false},{"id":-7,"name":"Resolved recently","jql":"resolutiondate >= -1w order by updated DESC","isSystem":true,"sharePermissions":[],"requiresLogin":false},{"id":-8,"name":"Updated recently","jql":"updated >= -1w order by updated DESC","isSystem":true,"sharePermissions":[],"requiresLogin":false}]
0.3
0