CVE-2020-13654: XWiki

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

XWiki Platform before 12.8 mishandles escaping in the property displayer.

Affected products

  • XWiki XWiki: before 12.8 (fixed in 12.8)

Published 2020-12-31. Last modified 2026-06-17.