|
Security policy: handling of contrib extensions not properly maintained
|
|
12
|
94
|
April 22, 2026
|
|
Error 500 instand of an error message when the user not are in the required group
|
|
3
|
120
|
June 6, 2025
|
|
Security Policy Amendment for allowing new security members
|
|
3
|
110
|
May 13, 2025
|
|
CKEditor support status and future
|
|
8
|
469
|
April 16, 2025
|
|
New channel for security fixes announcements in XWiki
|
|
8
|
395
|
January 31, 2025
|
|
Drop Security type in Jira
|
|
6
|
313
|
December 10, 2024
|
|
Introduce a new space which access is reserved to admins by default
|
|
7
|
397
|
November 5, 2024
|
|
XWiki Instance hacked
|
|
8
|
598
|
August 2, 2024
|
|
Update the default reset password link timeout to a longer value
|
|
10
|
2017
|
March 25, 2024
|
|
Add friction in some UI for better security
|
|
5
|
609
|
February 14, 2024
|
|
Even remote code executions of type "Bug" instead of type "Security" on jira.xwiki.org
|
|
1
|
490
|
January 12, 2024
|
|
Security Policy Process Amendment
|
|
4
|
446
|
December 8, 2023
|
|
Access request to security group in Jira.xwiki.org
|
|
2
|
407
|
December 4, 2023
|
|
Jira tickets for security issues
|
|
4
|
1358
|
October 10, 2023
|
|
Security warnings when using the latest XWiki version
|
|
9
|
1272
|
September 26, 2023
|
|
Security Policy Amendment to analyze vulnerabilities in dependencies
|
|
2
|
532
|
July 20, 2023
|
|
Formalize CVSS "Privileges Required" level for XWiki advisories
|
|
6
|
848
|
May 16, 2023
|
|
CVSS computation best practice for XSS
|
|
4
|
1004
|
May 16, 2023
|
|
Disclosing old fixed security issues
|
|
14
|
814
|
December 2, 2022
|
|
Security advisory template documented in Security policy
|
|
0
|
511
|
November 22, 2022
|
|
Security Policy Amendment: systematic vote for extending CVE embargo
|
|
5
|
503
|
November 4, 2022
|
|
Reminder about the importance of upgrading your XWiki instances
|
|
0
|
480
|
September 7, 2022
|
|
Add a .well-known/security.txt file in xwiki.org
|
|
6
|
2227
|
April 28, 2022
|
|
OpenID Connect Authenticator 1.29.1 released with important security fix
|
|
1
|
623
|
January 27, 2022
|
|
Log4J CVE-2021-44228 "Log4Shell" Zero-Day Vulnerability
|
|
1
|
3272
|
December 13, 2021
|
|
LTS updates with security issues
|
|
4
|
1079
|
July 30, 2021
|
|
Security issues disclosure for current cycle
|
|
2
|
537
|
June 30, 2021
|
|
SonarCloud Review
|
|
3
|
2603
|
May 28, 2021
|
|
Get rid of @Programming annnotation
|
|
5
|
514
|
January 25, 2021
|
|
[CRITICAL] Authenticated server side code execution without programming rights on User Dashboards
|
|
0
|
501
|
May 16, 2020
|